Impact
Cisco identified internal flaws in its SD‑WAN Controller and Manager, specifically improper resolution of symbolic links before file access. This CWE‑1284 weakness means an attacker could manipulate the file path resolution to read or modify files not intended to be accessible, potentially exposing configuration data or altering critical system files.
Affected Systems
The flaw affects Cisco Catalyst SD‑WAN Controller and Cisco Catalyst SD‑WAN Manager. No specific affected version ranges are listed, so all current deployments of these products should be considered vulnerable until an official patch is installed.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.7, indicating a high severity impact if exploited. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting that the likelihood of immediate exploitation is currently unknown. Because the description does not specify a remote trigger, the attack will most likely require either local access to the device or privileged interaction with the SD‑WAN software. Exploitation would proceed by supplying a crafted symbolic link that resolves to a privileged file path, bypassing the intended file access controls.
OpenCVE Enrichment