← Back to home
wid-sec-w-2026-0872  ·  Published 2026-03-25  ·  View on BSI CERT-Bund ↗

Cisco Catalyst SD-WAN Manager: Vulnerability allows Cross-Site Scripting

CVSS 5.4 MEDIUM

Risk Summary

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVEs (1)

Affected Vendors

Cisco

Affected Products (13)

Cisco · Catalyst SD-WAN Manager <20.12.5.3
Cisco · Catalyst SD-WAN Manager 20.12.5.3
Cisco · Catalyst SD-WAN Manager <20.12.6.1
Cisco · Catalyst SD-WAN Manager 20.12.6.1
Cisco · Catalyst SD-WAN Manager <20.15.4.2
Cisco · Catalyst SD-WAN Manager 20.15.4.2
Cisco · Catalyst SD-WAN Manager <20.18.2.1
Cisco · Catalyst SD-WAN Manager 20.18.2.1
Cisco · Catalyst SD-WAN Manager 20.13
Cisco · Catalyst SD-WAN Manager 20.14
Cisco · Catalyst SD-WAN Manager <20.15.5
Cisco · Catalyst SD-WAN Manager 20.15.5
Cisco · Catalyst SD-WAN Manager 20.16

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more