Cisco SD-WAN Software Information Disclosure Vulnerability
Description
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to access sensitive information. This vulnerability is due to improper protections on file access through the CLI. An attacker could exploit this vulnerability by running a CLI command that targets an arbitrary file on the local system. A successful exploit could allow the attacker to return portions of an arbitrary file, possibly resulting in the disclosure of sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated local attacker can read arbitrary files on Cisco SD-WAN Software via a CLI command, leading to information disclosure.
Vulnerability
An authenticated, local attacker can exploit an improper file access protection mechanism in the Cisco SD-WAN Software CLI to read arbitrary files on the system. The vulnerability stems from insufficient restrictions on file access through CLI commands, allowing a user with local access to target any file on the local filesystem. Affected versions include Cisco SD-WAN Software releases 18.4, 19.2, 20.3 (fixed in 20.3.5), 20.4 (fixed in 20.4.2), 20.5 (fixed in 20.5.2), and 20.6 (fixed in 20.6.1) [1].
Exploitation
An attacker must have authenticated access to the CLI of an affected Cisco SD-WAN device. No special privileges beyond standard user-level authentication are required. The attacker simply runs a specially crafted CLI command that specifies the path to an arbitrary file on the local system, bypassing intended access controls [1].
Impact
Successful exploitation allows the attacker to read portions of any file on the local system, potentially leading to the disclosure of sensitive information such as configuration files, credentials, or other confidential data. The attacker does not gain write or execute capabilities, but the information disclosure could be leveraged for further attacks [1].
Mitigation
Cisco has released fixed software versions: 20.3.5, 20.4.2, 20.5.2, and 20.6.1. For releases 18.4 and 19.2, Cisco recommends migrating to a fixed release. Customers should consult the Cisco Security Advisory and the associated bug ID for the most current information [1]. As of publication, no workaround is listed.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Cisco/Cisco SD-WAN Solutionv5Range: n/a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-Fhqh8pKXmitrevendor-advisoryx_refsource_CISCO
News mentions
0No linked articles in our index yet.