CyberRota Analysis
AI-GeneratedA critical vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to bypass authentication and gain admin-level access by exploiting improper URI encoding in HTTP requests. This could lead to unauthorized control over the affected systems, posing significant risks to network security and data integrity. Organizations using Cisco Catalyst SD-WAN Manager should prioritize immediate remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Related CVEs
Other vulnerabilities affecting the same vendor(s)