Cisco Security Update – 19 October 2023

Cisco has released a security update to address a vulnerability across the web UI of Cisco Catalyst SD-WAN Manager.

The addressed vulnerability could allow the remote authenticated attacker to exploit it by logging in to Cisco Catalyst SD-WAN Manager and issuing crafted requests using the web UI. After successful exploitation, the attacker could be able to obtain arbitrary files from the underlying Linux file system of the affected system.

Cisco Catalyst SD-WAN Manager Local File Inclusion Vulnerability (CVE-2023- 20261):

  • CVSS: 6.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2023-20261

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Cisco Security Advisory

References