Cisco Catalyst SD-WAN Manager
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*
- < 20.9
- = 20.9
- = 20.11
- = 20.12
- = 20.13
- = 20.14
- = 20.15
- = 20.16
- = 20.18
This vulnerability is being actively exploited in the wild.
A vulnerability exists in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager, prior to version 20.18. This vulnerability allows an authenticated, local attacker to gain DCA user privileges on the affected system. The issue arises because a credential file containing the DCA password is accessible to low-privileged users. An attacker with valid vmanage credentials can exploit this vulnerability by reading the credential file and using the DCA privileges to access other affected systems.
Exploitation of this vulnerability could lead to unauthorized access and privilege escalation, allowing the attacker to gain DCA user rights on the affected system and potentially access other systems with similar privileges.
Cisco has released software updates to address this vulnerability. Customers are advised to upgrade to version 20.18.2.1 or later. For additional guidance, consult the Cisco Catalyst SD-WAN Upgrade Matrix or contact the Cisco Technical Assistance Center (TAC).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.