VendorsCiscocatalyst_sd-wan_managerall versions
Vulnerabilities

Cisco Catalyst SD-WAN Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

91CVEs
CVE-2022-20716
Cisco SD-WAN Solution Improper Access Control Vulnerability
Published 2022-04-15 · Modified
7.8EPSS 0.002
CVE-2020-26074
Cisco SD-WAN vManage Privilege Escalation Vulnerability
Published 2024-11-18 · Analyzed
7.8EPSS 0.002
CVE-2025-20122
Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
Published 2025-05-07 · Analyzed
7.8EPSS 0.001
CVE-2026-20133
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
Published 2026-02-25 · Analyzed
7.5KEVEPSS 0.318
CVE-2020-26073
Cisco SD-WAN vManage Directory Traversal Vulnerability
Published 2024-11-18 · Analyzed
7.5EPSS 0.126
CVE-2026-20128
Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
Published 2026-02-25 · Analyzed
7.5KEVEPSS 0.078
CVE-2023-20262
A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crash, resulting in a DoS condition for SSH access only. This vulnerability does not prevent the system from continuing to function, and web UI access is not affected. This vulnerability is due to insufficient resource management when an affected system is in an error condition. An attacker could exploit this vulnerability by sending malicious traffic to the affected system. A successful exploit could allow the attacker to cause the SSH process to crash and restart, resulting in a DoS condition for the SSH service.
Published 2023-09-27 · Modified
7.5EPSS 0.007
CVE-2023-20253
A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacker to bypass authorization and allow the attacker to roll back the configuration on vManage controllers and edge router device. This vulnerability is due to improper access control in the cli-management interface of an affected system. An attacker with low-privilege (read only) access to the cli could exploit this vulnerability by sending a request to roll back the configuration on for other controller and devices managed by an affected system. A successful exploit could allow the attacker to to roll back the configuration on for other controller and devices managed by an affected system.
Published 2023-09-27 · Modified
7.1EPSS 0.002
CVE-2022-20930
Cisco SD-WAN Software Arbitrary File Corruption Vulnerability
Published 2022-09-30 · Modified
6.7EPSS 0.002
CVE-2021-1462
Cisco SD-WAN vManage Software Privilege Escalation Vulnerability
Published 2024-11-18 · Analyzed
6.7EPSS 0.002
CVE-2026-20262
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
Published 2026-06-15 · Analyzed
6.5KEVEPSS 0.282
CVE-2020-26065
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to an affected system. A successful exploit could allow the attacker to view arbitrary files on the affected system.
Published 2023-08-04 · Modified
6.5EPSS 0.017
CVE-2021-1491
Cisco SD-WAN vManage Software Information Disclosure Vulnerability
Published 2024-11-15 · Analyzed
6.5EPSS 0.013
CVE-2025-20187
Cisco SD-WAN Manager Software Arbitrary File Creation Vulnerability
Published 2025-05-07 · Analyzed
6.5EPSS 0.013
CVE-2021-1484
Cisco SD-WAN vManage Command Injection Vulnerability
Published 2024-11-15 · Analyzed
6.5EPSS 0.012
CVE-2021-1232
Cisco SD-WAN vManage Information Disclosure Vulnerability
Published 2024-11-18 · Analyzed
6.5EPSS 0.011
CVE-2022-20747
Cisco SD-WAN vManage Software Information Disclosure Vulnerability
Published 2022-04-15 · Modified
6.5EPSS 0.009
CVE-2020-3592
Cisco SD-WAN vManage Software Authorization Bypass Vulnerability
Published 2020-11-06 · Modified
6.5EPSS 0.008
CVE-2021-34712
Cisco SD-WAN vManage Software Cypher Query Language Injection Vulnerability
Published 2021-09-23 · Modified
6.5EPSS 0.007
CVE-2020-26066
Cisco SD-WAN vManage Software XML External Entity Vulnerability
Published 2024-11-18 · Analyzed
6.5EPSS 0.006
CVE-2023-20261
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to retrieve arbitrary files from an affected system. This vulnerability is due to improper validation of parameters that are sent to the web UI. An attacker could exploit this vulnerability by logging in to Cisco Catalyst SD-WAN Manager and issuing crafted requests using the web UI. A successful exploit could allow the attacker to obtain arbitrary files from the underlying Linux file system of an affected system. To exploit this vulnerability, the attacker must be an authenticated user.
Published 2023-10-18 · Modified
6.5EPSS 0.005
CVE-2022-20735
Cisco SD-WAN vManage Software Cross-Site Request Forgery Vulnerability
Published 2022-04-15 · Modified
6.5EPSS 0.005
CVE-2021-1483
Cisco SD-WAN vManage Software XML External Entity Vulnerability
Published 2024-11-15 · Analyzed
6.4EPSS 0.009
CVE-2020-3587
Cisco SD-WAN vManage Software Cross-Site Scripting Vulnerability
Published 2020-11-06 · Modified
6.4EPSS 0.006
CVE-2020-3590
Cisco SD-WAN vManage Software Cross-Site Scripting Vulnerability
Published 2020-11-06 · Modified
6.4EPSS 0.006
CVE-2021-1482
Cisco SD-WAN vManage Authorization Bypass Vulnerability
Published 2024-11-15 · Analyzed
6.4EPSS 0.006
CVE-2024-20475
Cisco SD-WAN vManage Cross-Site Scripting Vulnerability
Published 2024-09-25 · Analyzed
6.4EPSS 0.003
CVE-2020-3579
Cisco SD-WAN vManage Software Cross-Site Scripting Vulnerability
Published 2020-11-06 · Modified
6.1EPSS 0.008
CVE-2023-20098
A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands. An attacker with administrative privileges could exploit this vulnerability by running a system command containing directory traversal character sequences to target an arbitrary file. A successful exploit could allow the attacker to delete arbitrary files from the system, including files owned by root.
Published 2023-05-09 · Modified
6.0EPSS 0.005
CVE-2021-1512
Cisco SD-WAN Software Arbitrary File Corruption Vulnerability
Published 2021-05-06 · Modified
6.0EPSS 0.002
CVE-2025-20157
Cisco Catalyst vManage Certificate Validation Vulnerability
Published 2025-05-07 · Analyzed
5.9EPSS 0.003
CVE-2021-34700
Cisco SD-WAN vManage Software Information Disclosure Vulnerability
Published 2021-07-22 · Modified
5.5EPSS 0.003
CVE-2021-1546
Cisco SD-WAN Software Information Disclosure Vulnerability
Published 2021-09-23 · Modified
5.5EPSS 0.002
CVE-2025-20213
Cisco Catalyst SDWAN Manager Arbitrary File Overwrite Vulnerability
Published 2025-05-07 · Analyzed
5.5EPSS 0.002
CVE-2026-20122
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
Published 2026-02-25 · Analyzed
5.4KEVEPSS 0.250
CVE-2021-1466
Cisco SD-WAN vDaemon Buffer Overflow Vulnerability
Published 2024-11-15 · Analyzed
5.4EPSS 0.006
CVE-2025-20147
Cisco SD-WAN vManage Stored Cross-Site Scripting Vulnerability
Published 2025-05-07 · Analyzed
5.4EPSS 0.003
CVE-2026-20209
Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
Published 2026-05-14 · Analyzed
5.4EPSS 0.002
CVE-2026-20210
Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
Published 2026-05-14 · Analyzed
5.4EPSS 0.002
CVE-2026-20108
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published 2026-03-25 · Analyzed
5.4EPSS 0.002
← Prev2 / 3Next →