Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a critical zero-day authentication bypass in Cisco Catalyst SD-WAN Manager, allowing remote access to the Manager’s API as an admin user without login. Cisco has fixed releases available, and there is no workaround.
Active exploitation of an authentication bypass that grants unauthenticated administrative API access puts Cisco SD-WAN deployments at immediate risk. Organizations should move to a fixed release because the advisory says no workaround is available.