Cisco SD-WAN vEdge Software Access Control List Bypass Vulnerability
TL;DR 📌
A vulnerability in Cisco SD-WAN vEdge Software could allow unauthenticated remote attackers to bypass access control lists (ACLs) on affected devices. This vulnerability has a medium severity rating (CVSS 5.8). Cisco has released fixed software and workarounds are available.
What happened 🕵️♂️
A vulnerability has been identified in the access control list (ACL) processing of IPv4 packets within Cisco SD-WAN vEdge Software. This flaw allows an unauthenticated remote attacker to bypass configured ACLs due to improper enforcement of the implicit deny rule at the end of an ACL. By exploiting this vulnerability, attackers can send unauthorized traffic to an affected device’s interface, potentially compromising network security.
Affected products 🖥️
The vulnerability affects Cisco SD-WAN vEdge Routers running vulnerable releases of Cisco SD-WAN vEdge Software. Specifically, the following versions are impacted:
- Cisco SD-WAN vEdge Software Release 20.9 (first fixed release: 20.9.7)
- Cisco SD-WAN vEdge Software Release 20.8 and earlier (not vulnerable)
- Cisco SD-WAN vEdge Software Release 20.10 and later (not vulnerable)
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 20.8 and earlier | Not vulnerable | |
| 20.9 | 20.9.7 | |
| 1.0 | Initial public release. | |
| Cisco SD-WAN vEdge Software | 20.9.7 | 20.9 |
Workarounds 🧯
Administrators can implement a workaround by determining the most suitable ACL for their needs and configuring that single ACL type on the affected interface. However, it is crucial to evaluate the applicability and potential impact of this workaround in your specific environment before deployment.
Risk in context 🎯
The risk associated with this vulnerability is considered medium (CVSS 5.8). The exposure is primarily internet-facing, as it allows unauthenticated access. While there is no immediate availability impact, successful exploitation could lead to unauthorized access to network resources protected by ACLs. Organizations should assess their specific environments to understand the potential consequences of this vulnerability.
Fast facts ⚡
- Vulnerability: ACL Bypass in Cisco SD-WAN vEdge Software
- CVSS Score: 5.8 (Medium)
- Exploitation: Unauthenticated remote attackers can bypass ACLs
- Fixed Software: 20.9.7 for affected versions
- Workaround: Configure a single ACL type on the interface
For leadership 🧭
Executive summary. Cisco SD-WAN vEdge routers running the 20.9 train before 20.9.7 can let unauthenticated traffic slip past configured interface ACLs, undermining a control organisations rely on to segment or restrict access. There is no active exploitation reported, so this can go through a normal patch cycle rather than an emergency change.
Why it matters:
- The bug sits in IPv4 ACL processing on vEdge Cloud and vEdge Router interfaces, meaning the very access lists administrators configure to restrict traffic may not actually block it.
- No authentication is required to exploit the bypass, so any traffic reaching an affected interface could reach resources the ACL was meant to protect.
- Only Release 20.9 before 20.9.7 is affected; 20.8 and earlier, and 20.10 and later, are not vulnerable, so exposure depends on which train is running.
- A workaround exists (using a single consistent ACL type on the interface) for sites that cannot upgrade immediately.
Now / Next / Later:
- Now: Identify any vEdge Cloud or vEdge Router instances running SD-WAN Software 20.9 prior to 20.9.7 and review what ACLs on their interfaces are actually meant to be enforcing.
- Next: Upgrade affected 20.9 devices to 20.9.7 in the next scheduled change window; where upgrade isn’t yet possible, apply the workaround of configuring a single ACL type per interface after assessing its impact.
- Later: Add ACL enforcement verification to post-upgrade checks for SD-WAN vEdge deployments so that access-control assumptions are confirmed rather than assumed after future software changes.