A vulnerability has been discovered in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow for authentication bypass. Cisco Catalyst SD-WAN Manager is the centralized dashboard used to monitor and manage SD-WAN fabric devices, in some deployments up to several thousand devices from a single console. An attacker could exploit this vulnerability by sending a specially crafted HTTP request with a URI-encoded character to the Manager's API, which could allow the request to skip an authentication rule intended to restrict access to a specific endpoint. Successful exploitation of this vulnerability could result in an unauthenticated, remote attacker gaining admin-level access to the affected system's API, and by extension the ability to view or modify the configuration of every SD-WAN device that Manager instance controls. This vulnerability affects the product regardless of device configuration; there is no feature toggle or configuration setting that removes the exposure.
Read more... Cyber Security Advisories - MS-ISAC