Cisco Catalyst SD-WAN Manager Certificate Validation Vulnerability Allowing Sensitive Information Access

Vulnerability

A vulnerability exists in the certificate validation process of Cisco Catalyst SD-WAN Manager (formerly Cisco SD-WAN vManage). This issue could enable an unauthenticated, remote attacker to access sensitive information. The vulnerability arises from improper validation of certificates used by the Smart Licensing feature. An attacker with a privileged network position could exploit this by intercepting Internet traffic, potentially gaining access to sensitive data, including credentials used by the device to connect to Cisco cloud services.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, including credentials for Cisco cloud services.

Remediation

Cisco has released software updates to address this vulnerability. Customers are advised to upgrade to a fixed release. For guidance on upgrading, consult the Cisco Security Advisories page or contact the Cisco Technical Assistance Center (TAC) or a contracted maintenance provider.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
6.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.