Cisco Catalyst SD-WAN Manager
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*
- >= 20.9.2, < 20.9.7
- ~20.15
A vulnerability exists in the application data endpoints of Cisco Catalyst SD-WAN Manager (formerly Cisco SD-WAN vManage), allowing authenticated, remote attackers to write arbitrary files to the system. This issue arises from inadequate validation of requests to APIs, enabling attackers to send malicious requests that could exploit directory traversal vulnerabilities and write files to arbitrary locations on the affected system.
Exploitation of this vulnerability could lead to unauthorized file creation, potentially allowing for further attacks such as code execution or manipulation of the application environment.
Cisco has released software updates to address this vulnerability. Customers should consult the Cisco Security Advisories page for guidance on upgrading to a fixed release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.