wid-sec-w-2026-0872
·
Published 2026-03-25
·
View on BSI CERT-Bund ↗
Cisco Catalyst SD-WAN Manager: Vulnerability allows Cross-Site Scripting
CVSS 5.4
MEDIUM
Risk Summary
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
CVEs (1)
Affected Vendors
Cisco
Affected Products (13)
Cisco
·
Catalyst SD-WAN Manager
<20.12.5.3
Cisco
·
Catalyst SD-WAN Manager
20.12.5.3
Cisco
·
Catalyst SD-WAN Manager
<20.12.6.1
Cisco
·
Catalyst SD-WAN Manager
20.12.6.1
Cisco
·
Catalyst SD-WAN Manager
<20.15.4.2
Cisco
·
Catalyst SD-WAN Manager
20.15.4.2
Cisco
·
Catalyst SD-WAN Manager
<20.18.2.1
Cisco
·
Catalyst SD-WAN Manager
20.18.2.1
Cisco
·
Catalyst SD-WAN Manager
20.13
Cisco
·
Catalyst SD-WAN Manager
20.14
Cisco
·
Catalyst SD-WAN Manager
<20.15.5
Cisco
·
Catalyst SD-WAN Manager
20.15.5
Cisco
·
Catalyst SD-WAN Manager
20.16
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more