Cisco Catalyst SD-WAN Manager(Cisco SD-WAN vManage)是美国思科(Cisco)公司的一个高度可定制的仪表板。可简化和自动化 Cisco SD-WAN 的部署、配置、管理和操作。 Cisco Catalyst SD-WAN Manager存在信息泄露漏洞,该漏洞源于文件系统访问限制不足,可能导致远程攻击者读取底层操作系统敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Catalyst SD-WAN Manager | 17.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20127 | 10.0 CRITICAL | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability |
| CVE-2026-20129 | 9.8 CRITICAL | Cisco Catayst SD-WAN Authentication Bypass Vulnerability |
| CVE-2026-20126 | 8.8 HIGH | Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability |
| CVE-2026-20048 | 7.7 HIGH | Cisco NX-OS Software SNMP Denial of Service Vulnerability |
| CVE-2026-20128 | 7.5 HIGH | Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability |
| CVE-2026-20033 | 7.4 HIGH | Cisco NX-OS Software Denial of Service Vulnerability |
| CVE-2026-20010 | 7.4 HIGH | Cisco Nexus 3000 and 9000 Series Switches Link Layer Discovery Protocol Denial of Service |
| CVE-2026-20051 | 7.4 HIGH | Cisco Nexus 3600-R and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vu |
| CVE-2026-20099 | 6.7 MEDIUM | Cisco UCS Manager and FXOS Software Command Injection Vulnerability |
| CVE-2026-20036 | 6.5 MEDIUM | Cisco UCS Manager Software Command Injection Vulnerability |
| CVE-2026-20107 | 5.5 MEDIUM | Cisco Application Policy Infrastructure Controller Denial of Service Vulnerability |
| CVE-2026-20122 | 5.4 MEDIUM | Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability |
| CVE-2026-20091 | 4.8 MEDIUM | Cisco UCS Manager and FXOS Software Stored Cross-Site Scripting Vulnerability |
| CVE-2026-20037 | 4.4 MEDIUM | Cisco UCS Manager File Write Vulnerability |
No comments yet