Skip to content

Cisco SD-WAN vManage Unauthenticated REST API Access Vulnerability - 20230717004

Overview

The WA SOC has observed a critical vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software, which could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. This vulnerability only affects the REST API and does not affect the web-based management interface or the CLI. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

What is the vulnerability?

Cisco Security Advisories CVE- 2023-20214- CVSS v3 Base Score:9.1

What is vulnerable?

The vulnerability affects the Cisco SD-WAN vManage software.

What has been observed?

There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of one month (refer Patch Management):

Additional References