Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability

🚨SEVERITY: MEDIUM — CVSS 5.5Security Advisory

TL;DR 📌

  • A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To exploit this vulnerability, the attacker must have valid read-only credentials with CLI access on the affected system. This vulnerability is due…
  • Highest CVSS: 5.5 (Medium).
  • Fix available — see the first fixed release below.
  • CVEs: CVE-2025-20213.

What it is

CVE-2025-20213 is a local privilege escalation flaw in the CLI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). It stems from improper access controls on files stored on the local file system.

An attacker needs valid, low-privilege read-only credentials with CLI access to the affected device — this is not remotely exploitable by an unauthenticated party, and it isn’t a data-plane issue. With that access, the attacker can run a series of crafted commands to overwrite arbitrary files on the local file system.

The impact is a full jump in privilege: a successful exploit lets a read-only CLI user gain root privileges on the device. Cisco rates this 5.5 (Medium) under CVSS 3.1 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N), reflecting the local access requirement but the high integrity impact once triggered.

There are no workarounds. Cisco is not aware of any public announcements or malicious use of this vulnerability.

What to do

  • Upgrade Cisco Catalyst SD-WAN Manager to a fixed release: 20.12.5 (for the 20.12 train) or 20.16.1 (for the 20.16 train).
  • If running earlier trains not listed above (e.g. those flagged in the advisory as having reached End of Software Maintenance or entering end-of-life), migrate to one of the fixed releases rather than waiting for a patch on the old train.
  • Since no workaround exists, treat the upgrade as the only mitigation — there’s nothing to configure around this in the interim.
  • Review who holds read-only CLI credentials on SD-WAN Manager instances; this flaw is only reachable by someone who already has that low-privilege access, so tightening credential issuance and rotation reduces exposure while patching is scheduled.
  • Check Cisco’s advisory bundle for the related Catalyst SD-WAN Manager issues (privilege escalation, arbitrary file creation, certificate validation, stored XSS) published alongside this one, as affected estates often need to address more than one in the same maintenance window.

Fixed releases

Affected release First fixed release
20.12 20.12.5
20.16 20.16.1

For leadership 🧭

Executive summary. Anyone holding a read-only CLI account on SD-WAN Manager can escalate to full root control of the device by overwriting local files, and there is no interim workaround. Because this requires no network exposure beyond existing credentials, it should be scheduled into the next maintenance window rather than treated as an emergency.

Why it matters:

  • Exploitation needs only valid low-privilege, read-only CLI credentials on SD-WAN Manager — no additional network access or unauthenticated path is required.
  • A successful attack overwrites arbitrary files on the local file system and grants the attacker root privileges, turning a limited support account into full device control.
  • No workaround exists, so exposure persists until the device is upgraded to 20.12.5 or 20.16.1.
  • This advisory is one of several published together for Catalyst SD-WAN Manager, including a separate privilege escalation and arbitrary file creation issue, so estates may need to patch more than one flaw at once.

Now / Next / Later:

  • Now: Identify every Cisco Catalyst SD-WAN Manager instance and check which release train it runs, then confirm who currently holds read-only CLI credentials on each.
  • Next: Upgrade affected SD-WAN Manager instances to 20.12.5 or 20.16.1 in the next scheduled maintenance window, migrating off any older or end-of-life train rather than waiting for a train-specific fix.
  • Later: Tighten issuance and rotation of read-only CLI accounts on SD-WAN Manager, and track the companion advisories in the same bundle (privilege escalation, arbitrary file creation, certificate validation, stored XSS) so they’re patched together rather than piecemeal.

Source