CISOOnline

Cisco SD-WAN Manager hit by zero-day admin access attack

“While every configuration is affected, the practical exposure is not identical across organizations: an internet-accessible management interface presents a much more immediate risk than one isolated within a tightly controlled administrative network,” Grover said, reinforcing Cisco’s advice.

Compromising the management layer can give an attacker considerably more leverage than having access to an individual edge device; Cisco’s official documentation says SD-WAN Manager clusters can support thousands of Cisco Catalyst SD-WAN devices, with supported configurations scaling to as many as 12,500 devices.

The effects could reach well beyond the management servers, Grover noted. “Administrative API access could potentially allow an attacker to understand the network topology, modify templates or policies, weaken segmentation, establish persistence or distribute unauthorized configuration changes across multiple locations,” she said.



Source link