Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

MonitorCVSS 6.5cisco-sa-sdwan-infodis-SPuJBDCeAug 5, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in Cisco Catalyst SD-WAN Manager's web-based management interface allows authenticated, low-privileged remote attackers to view sensitive authentication credentials in plaintext. The vulnerability stems from insufficient access control enforcement for specific template types that are not included in the encryption allowlist. An attacker with low-privilege credentials could exploit this by viewing logs on the local system or remote logging server, potentially compromising network infrastructure and connected services.

What this means
What could happen
An authenticated user with low privileges could read logs containing plaintext authentication credentials stored in the SD-WAN Manager, allowing them to compromise network infrastructure and access connected services.
Who's at risk
Network and SD-WAN operators managing Cisco Catalyst SD-WAN Manager deployments should be aware that low-privileged administrative users could potentially read plaintext credentials from system logs, compromising the security of the entire SD-WAN and connected network infrastructure.
How it could be exploited
An attacker with valid low-privilege credentials can access the web management interface and view logs through the local system or remote logging server, where sensitive authentication data is stored unencrypted due to insufficient access controls on certain template types.
Prerequisites
  • Valid low-privilege user credentials for Catalyst SD-WAN Manager web interface
  • Network access to the management interface (typically port 443)
  • Access to logs on the local system or connected remote logging server
remotely exploitableauthentication required (low privilege)low complexityno patch available mentioned for specific versions
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (1)
ProductAffected VersionsFix Status
Catalyst SD-WAN ManagerAll versionsFix available
Remediation & Mitigation
0/4
Do now
0/2
HARDENINGRestrict access to the SD-WAN Manager web interface to trusted administrative networks only using firewall rules
HARDENINGLimit user privileges to the minimum required for job functions and audit user roles regularly
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpgrade Cisco Catalyst SD-WAN Manager to the patched version released by Cisco
Long-term hardening
0/1
HARDENINGSecure remote logging servers with encryption and access controls to prevent unauthorized log retrieval
API: /api/v1/advisories/78c3c514-c057-4f01-bd14-5f696125f652

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.