📦 Catalyst Sd Wan Manager

by Cisco

🔍 What is Catalyst Sd Wan Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-20129

CRITICAL CVSS 9.8 Feb 25, 2026

This critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to gain netadmin privileges by sending crafted API requests. Systems running ...

CVE-2026-20127

CRITICAL CVSS 10.0 Feb 25, 2026

This critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to gain administrative privileges. Attackers can manipulate ne...

CVE-2023-20252

CRITICAL CVSS 9.8 Sep 27, 2023

This critical vulnerability in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to bypass authentication via SAML API flaws, gaining unauthorized access as any user. Organizations...

CVE-2023-20214

CRITICAL CVSS 9.1 Aug 3, 2023

An unauthenticated remote attacker can exploit insufficient request validation in the REST API of Cisco SD-WAN vManage software to gain read or limited write permissions to the configuration. This aff...

CVE-2021-1468

CRITICAL CVSS 9.8 May 6, 2021

Multiple vulnerabilities in Cisco SD-WAN vManage Software allow unauthenticated remote attackers to execute arbitrary code or access sensitive information, and authenticated local attackers to escalat...

CVE-2021-1505

CRITICAL CVSS 9.8 May 6, 2021

CVE-2021-1505 is a critical vulnerability in Cisco SD-WAN vManage software that allows unauthenticated remote attackers to execute arbitrary code or access sensitive information. It also enables authe...

CVE-2021-1508

CRITICAL CVSS 9.8 May 6, 2021

Multiple vulnerabilities in Cisco SD-WAN vManage Software allow unauthenticated remote attackers to execute arbitrary code or access sensitive information, and authenticated local attackers to escalat...

CVE-2021-1300

CRITICAL CVSS 9.8 Jan 20, 2021

CVE-2021-1300 is a critical buffer overflow vulnerability in Cisco SD-WAN products that allows unauthenticated remote attackers to execute arbitrary code or cause denial of service. Affected systems i...

CVE-2026-20126

HIGH CVSS 8.8 Feb 25, 2026

This vulnerability in Cisco Catalyst SD-WAN Manager allows authenticated local users with low privileges to escalate to root privileges through the REST API. It affects organizations using vulnerable ...

CVE-2025-20122

HIGH CVSS 7.8 May 7, 2025

This vulnerability allows authenticated local attackers with read-only privileges on Cisco Catalyst SD-WAN Manager to escalate to root privileges on the underlying operating system through insufficien...

CVE-2020-26074

HIGH CVSS 7.8 Nov 18, 2024

This vulnerability in Cisco SD-WAN vManage software allows authenticated local attackers to gain escalated privileges by exploiting improper path validation in file transfer functions. Attackers can o...

CVE-2020-26071

HIGH CVSS 8.4 Nov 18, 2024

This vulnerability allows authenticated local attackers on Cisco SD-WAN devices to create or overwrite arbitrary files through insufficient input validation in CLI commands. This could lead to denial ...

CVE-2022-20775

HIGH CVSS 7.8 Sep 30, 2022

This vulnerability in Cisco SD-WAN Software allows authenticated local attackers to gain root privileges by exploiting improper access controls in the CLI. Attackers can execute arbitrary commands as ...

CVE-2022-20739

HIGH CVSS 7.3 Apr 15, 2022

This vulnerability allows authenticated low-privileged users on Cisco SD-WAN vManage systems to escalate privileges to root by injecting commands into a file executed by administrators. Attackers must...

CVE-2021-1528

HIGH CVSS 7.8 Jun 4, 2021

This vulnerability in Cisco SD-WAN Software allows authenticated local attackers to escalate privileges to root by exploiting improper access restrictions on privileged processes. It affects Cisco SD-...

CVE-2021-1513

HIGH CVSS 7.5 May 6, 2021

This vulnerability in Cisco SD-WAN Software allows unauthenticated remote attackers to cause affected devices to reload by sending malformed packets, resulting in denial of service. It affects Cisco S...

CVE-2021-1284

HIGH CVSS 8.8 May 6, 2021

This vulnerability allows an unauthenticated attacker with network access to adjacent Cisco SD-WAN vEdge devices to bypass authentication and authorization on Cisco SD-WAN vManage Software. The attack...

CVE-2021-1479

HIGH CVSS 7.8 Apr 8, 2021

CVE-2021-1479 allows unauthenticated remote attackers to execute arbitrary code on Cisco SD-WAN vManage software, or authenticated local attackers to gain escalated privileges. This affects organizati...

CVE-2021-1137

HIGH CVSS 7.8 Apr 8, 2021

This vulnerability in Cisco SD-WAN vManage Software allows unauthenticated remote attackers to execute arbitrary code or authenticated local attackers to gain escalated privileges. It affects organiza...

CVE-2025-20213

MEDIUM CVSS 5.5 May 7, 2025

This vulnerability allows authenticated local attackers with read-only CLI access to overwrite arbitrary files on Cisco Catalyst SD-WAN Manager devices. By exploiting improper file access controls, at...

CVE-2025-20216

MEDIUM CVSS 4.7 May 7, 2025

This vulnerability allows unauthenticated remote attackers to inject HTML content into authenticated users' browsers via the Cisco Catalyst SD-WAN Manager web interface. Attackers can exploit this by ...

CVE-2025-20187

MEDIUM CVSS 6.5 May 7, 2025

This vulnerability in Cisco Catalyst SD-WAN Manager allows authenticated remote attackers to write arbitrary files via API requests due to improper input validation. Attackers can conduct directory tr...

CVE-2025-20157

MEDIUM CVSS 5.9 May 7, 2025

An improper certificate validation vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage) allows attackers to intercept Smart Licensing traffic and steal sensitive credentials. Unauthentica...

CVE-2021-1462

MEDIUM CVSS 6.7 Nov 18, 2024

This vulnerability allows authenticated local administrators on Cisco SD-WAN vManage Software to escalate their privileges to root level. Attackers need valid administrator credentials to exploit this...

CVE-2021-1232

MEDIUM CVSS 6.5 Nov 18, 2024

This vulnerability allows authenticated remote attackers to read arbitrary files on Cisco SD-WAN vManage systems through the web management interface. It affects organizations using Cisco SD-WAN vMana...

CVE-2021-1482

MEDIUM CVSS 6.4 Nov 15, 2024

This vulnerability allows authenticated remote attackers to bypass authorization checks in Cisco SD-WAN vManage's web management interface, potentially accessing sensitive information. It affects orga...

CVE-2021-1484

MEDIUM CVSS 6.5 Nov 15, 2024

This vulnerability in Cisco SD-WAN vManage Software allows authenticated remote attackers to inject arbitrary commands through the web UI's device template configuration, potentially causing a denial ...

CVE-2021-1464

MEDIUM CVSS 5.0 Nov 15, 2024

This vulnerability in Cisco SD-WAN vManage Software allows authenticated remote attackers to bypass authorization checks and access restricted configuration data. The issue stems from insufficient inp...

CVE-2021-1470

MEDIUM CVSS 4.9 Nov 15, 2024

This SQL injection vulnerability in Cisco SD-WAN vManage allows authenticated attackers to execute malicious SQL queries against the database. It affects organizations using vulnerable versions of Cis...