Cisco Catalyst SD-WAN Manager Multiple Vulnerabilities (cisco-sa-sdwan-authbp-qwCX8D4v)

high Nessus Plugin ID 299999

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco Catalyst SD-WAN Manager is affected by multiple vulnerabilities:

- A vulnerability could allow an authenticated, local attacker to escalate privileges on the underlying operating system. (CVE-2026-20126)

- A vulnerability could allow an unauthenticated, remote attacker to access sensitive information from the affected system. (CVE-2026-20133)

- A vulnerability could allow an authenticated, remote attacker to modify data and impact availability of the system. (CVE-2026-20122)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCws33583, CSCws33584, CSCws33586, CSCws93470.

See Also

http://www.nessus.org/u?e8b27ea7

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws33583

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws33584

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws33586

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws93470

Plugin Details

Severity: High

ID: 299999

File Name: cisco-sa-sdwan-authbp-qwCX8D4v.nasl

Version: 1.1

Type: local

Family: CISCO

Published: 2/26/2026

Updated: 2/26/2026

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-20133

CVSS v3

Risk Factor: High

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2026-20126

Vulnerability Information

CPE: cpe:/o:cisco:sd-wan_firmware

Required KB Items: Cisco/Viptela/Version

Patch Publication Date: 2/25/2026

Vulnerability Publication Date: 2/25/2026

Reference Information

CVE: CVE-2026-20122, CVE-2026-20126, CVE-2026-20133