cisco-sa-sdwan-webauth-xr8beuuU: Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An unauthenticated remote attacker who can send HTTP requests to the affected system's API can attempt exploitation. Successful exploitation provides access to the API with admin-user privileges.
What does an attacker need to do to bypass authentication?
The attacker must send a crafted HTTP request that uses URI encoding to bypass an authentication rule protecting a specific API endpoint.
Is there a mitigation if updates cannot be installed immediately?
No. The available information states that there are no workarounds that address this vulnerability; Cisco software updates are the stated remediation.