Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
A vulnerability in Cisco Catalyst SD-WAN Manager's web-based management interface allows authenticated, low-privileged remote attackers to view sensitive authentication credentials in plaintext. The vulnerability stems from insufficient access control enforcement for specific template types that are not included in the encryption allowlist. An attacker with low-privilege credentials could exploit this by viewing logs on the local system or remote logging server, potentially compromising network infrastructure and connected services.
- Valid low-privilege user credentials for Catalyst SD-WAN Manager web interface
- Network access to the management interface (typically port 443)
- Access to logs on the local system or connected remote logging server
Patching may require device reboot — plan for process interruption
/api/v1/advisories/78c3c514-c057-4f01-bd14-5f696125f652Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.