A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint.
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
About this summary. This is a short, independently written summary of an article first published by Cisco PSIRT. Cyber Security News did not report or verify the underlying story. Read the original: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU?vs_f=Cisco%20Security%20Advisory%26vs_cat%3DSecurity%20Intelligence%26vs_type%3DRSS%26vs_p%3DCisco%20Catalyst%20SD-WAN%20Manager%20API%20Authentication%20Bypass%20Vulnerability%26vs_k%3D1
Source attribution: headline and facts are from Cisco PSIRT (sec.cloudapps.cisco.com). Summary method: excerpt of the source description. See our source attribution policy.





