Impact
A flaw in the web UI of Cisco Catalyst SD-WAN Manager allows an attacker who has authenticated to the management console to upload a specially crafted file. Because the upload API does not validate the supplied file path, the attacker can create or overwrite any file on the server’s filesystem. If the overwritten file is a system service or binary, the attacker could run arbitrary code with the privileges of the management service, potentially reaching root. The vulnerability is a classic example of CWE‑22: Path Traversal, leading to unauthorized file modification.
Affected Systems
The vulnerability affects any deployment of Cisco Catalyst SD-WAN Manager that exposes the web UI file‑upload endpoint. Specific product versions are not listed in the advisory, so all currently installed versions are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate level of severity, while the EPSS score of 2% suggests it is a low‑probability event. Because it is listed in the CISA KEV catalog, it has been observed in the wild or is considered high threat. Exploit requires valid credentials with at least a lower‑privileged role, meaning that an attacker must first gain account access—through compromised credentials, phishing, or other means—to exploit the flaw. Once authenticated, the attacker can write arbitrary files, which may lead to privilege escalation and full system compromise.
OpenCVE Enrichment