Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-1284.
Published: 2026-08-05
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cisco identified internal flaws in its SD‑WAN Controller and Manager, specifically improper resolution of symbolic links before file access. This CWE‑1284 weakness means an attacker could manipulate the file path resolution to read or modify files not intended to be accessible, potentially exposing configuration data or altering critical system files.

Affected Systems

The flaw affects Cisco Catalyst SD‑WAN Controller and Cisco Catalyst SD‑WAN Manager. No specific affected version ranges are listed, so all current deployments of these products should be considered vulnerable until an official patch is installed.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.7, indicating a high severity impact if exploited. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting that the likelihood of immediate exploitation is currently unknown. Because the description does not specify a remote trigger, the attack will most likely require either local access to the device or privileged interaction with the SD‑WAN software. Exploitation would proceed by supplying a crafted symbolic link that resolves to a privileged file path, bypassing the intended file access controls.

Generated by OpenCVE AI on August 5, 2026 at 18:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch for Cisco Catalyst SD‑WAN Controller and Manager that addresses the improper link resolution flaw.
  • If an immediate patch is unavailable, restrict symbolic link usage in the system’s file access configuration and enforce strict path validation rules to prevent malicious link exploitation.
  • Verify that file and directory permissions on the SD‑WAN appliance are set to the principle of least privilege, ensuring that non‑admin users cannot create or modify links that could escape intended directories.

Generated by OpenCVE AI on August 5, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 21:30:00 +0000


Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco catalyst Sd-wan Manager
Cisco cisco Catalyst Sd-wan Controller
Vendors & Products Cisco
Cisco catalyst Sd-wan Manager
Cisco cisco Catalyst Sd-wan Controller

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-1284.
Title Cisco Catalyst SD-WAN Security Hardening Release - Memory Corruption Vulnerabilities
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Cisco Catalyst Sd-wan Manager Cisco Catalyst Sd-wan Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-14T21:00:50.858Z

Reserved: 2025-10-08T11:59:15.410Z

Link: CVE-2026-20313

cve-icon Vulnrichment

Updated: 2026-08-14T21:00:50.858Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T17:16:52.437

Modified: 2026-08-14T21:17:17.417

Link: CVE-2026-20313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:46Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input