Impact
The flaw results from improper input validation, classified under CWE-20. The vulnerability could allow an attacker with crafted input to influence the behavior of the Cisco Catalyst SD‑WAN Controller or Manager. The advisory does not describe the specific exploitation mechanism; however, the high CVSS score of 9.9 indicates a severe risk. Based on the score, it is inferred that the issue could potentially enable significant compromise of system functionality or data availability.
Affected Systems
This vulnerability affects Cisco Catalyst SD‑WAN Controller and Cisco Catalyst SD‑WAN Manager appliances. No specific firmware or software versions are identified in the advisory, so all existing deployments of these products should be considered vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 9.9 marks this issue as critical, and the lack of an EPSS score means the official probability of exploitation is not quantified. The advisory does not list the vulnerability in CISA’s KEV catalog. The advisory does not detail the attack vector. However, given typical exploitation of input‑validation vulnerabilities and the remote nature of SD‑WAN management interfaces, it is inferred that a remote attacker could potentially target exposed APIs or interfaces. No specific privileges beyond access to management interfaces appear required, so environments with unrestricted network access remain at elevated risk.
OpenCVE Enrichment