Impact
The vulnerability is an improper link resolution before file access flaw classified as CWE‑59. During file reads the system does not correctly verify that a file or directory is not a symbolic link that points to another location, which allows an attacker to read arbitrary files whose names are supplied through the link resolution process. The impact is the ability to read sensitive configuration or credential files and thereby compromise confidentiality of the SD‑WAN deployment.
Affected Systems
The flaw affects Cisco Catalyst SD‑WAN Controller and Cisco Catalyst SD‑WAN Manager products. No specific version information was provided in the advisory, so all current and older releases are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 9.1 reflects a high severity with a high impact. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. While the specific attack vector is not detailed, the context of SD‑WAN management suggests that remote exploitation through the control plane or management interfaces is plausible, especially if an attacker can supply a crafted link name. The high score indicates that the flaw is exploitable with moderate complexity and that successful exploitation would compromise confidential information. Therefore, the risk to an organization deploying these products is significant until a vendor‑issued fix is implemented.
OpenCVE Enrichment