CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

A Critical Vulnerability in Cisco SD-WAN Manager Exposes Hundreds of Networks to Exploitation

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in the Cisco Catalyst Software-Defined Wide Area Network (SD-WAN) Manager to its Known Exploited Vulnerabilities catalog. The flaw, designated as CVE-2023-2018, allows an attacker with administrative privileges to bypass authentication and access sensitive information on vulnerable systems.

This vulnerability affects numerous organizations worldwide that rely on Cisco’s SD-WAN solution for secure connectivity between remote sites and data centers. According to recent estimates, hundreds of networks are potentially exposed to exploitation due to this flaw. The problem stems from a design weakness in the manager component of the SD-WAN system, which enables an attacker to access sensitive configuration settings and even execute arbitrary code on vulnerable systems.

The vulnerability is exploited by manipulating session tokens, allowing an unauthorized actor to gain elevated privileges within the network. This can lead to lateral movement and potentially devastating consequences, including complete takeover of the affected network or exfiltration of sensitive data. The fact that this flaw has been added to CISA’s KEV catalog indicates that it is being actively exploited by malicious actors.

The significance of this vulnerability lies in its potential impact on organizations operating in critical infrastructure sectors, such as finance and healthcare. Attackers exploiting CVE-2023-2018 can gain unfettered access to sensitive systems, compromising confidentiality and integrity. Moreover, the widespread adoption of SD-WAN technology means that hundreds of networks are potentially exposed to this threat.

Cisco has released patches for affected versions of its SD-WAN Manager software, which should be applied as soon as possible by administrators responsible for vulnerable systems. Furthermore, network owners must conduct thorough risk assessments and implement robust security measures to prevent exploitation attempts.

To mitigate the risks associated with this vulnerability, organizations are advised to apply the latest patches, implement strong access controls, and monitor their networks for signs of unauthorized activity. This critical vulnerability serves as a stark reminder of the importance of timely patching and robust network security practices in today’s digital landscape.


Source: The Hacker News — 2026-10-01