Cisco Catalyst SD-WAN Manager Certificate Validation Vulnerability

🚨SEVERITY: MEDIUM β€” CVSS 5.9Security Advisory

TL;DR πŸ“Œ

  • A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper validation of certificates that are used by the Smart Licensing feature. An attacker with a privileged network position could exploit this vulnerability…
  • Highest CVSS: 5.9 (Medium).
  • Fix available β€” see the first fixed release below.
  • CVEs: CVE-2025-20157.

What it is

CVE-2025-20157 is a certificate validation flaw in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage), specifically in the handling of certificates used by the Smart Licensing feature. The software fails to properly validate these certificates when connecting to Cisco’s cloud licensing services.

Exploitation requires an attacker to hold a privileged network position that lets them intercept traffic sent over the internet between SD-WAN Manager and Cisco’s cloud services β€” effectively a man-in-the-middle scenario rather than direct network access to the device. No authentication to SD-WAN Manager itself is needed for the attacker to carry out the interception.

A successful attack lets the attacker read sensitive information in that intercepted traffic, including credentials that the device uses to authenticate to Cisco cloud services. This is confidentiality-only impact: there’s no integrity or availability effect, and the CVSS vector reflects that (C:H/I:N/A:N), along with a high attack complexity (AC:H) given the need for a privileged network position.

This affects Catalyst SD-WAN Manager deployments configured to connect to Cisco-hosted Smart Licensing services. It’s one of several SD-WAN Manager advisories published together by Cisco; this one is specific to the certificate validation issue.

What to do

  • Upgrade Catalyst SD-WAN Manager to a fixed release. Cisco lists fixes as: 20.9 β†’ 20.9.7, 20.12 β†’ 20.12.5, 20.15 β†’ 20.15.2. Releases 20.11.x, 20.13.x and 20.14.x have no fix and should be migrated to a fixed train instead. 20.16 is not vulnerable.
  • There are no workarounds. If you’re on an affected train and can’t upgrade immediately, be aware that traffic to Cisco Smart Licensing services remains exposed to interception in a privileged-network-position scenario until you patch.
  • Check whether your systems are on End of Software Maintenance branches (Cisco flags 20.111, 20.131 and 20.142 as EoSM in the advisory) β€” these require migration to a supported release rather than a point fix.
  • If Smart Licensing credentials may have already traversed a compromised network path, consider rotating them as a precaution once patched.

Fixed releases

Affected release First fixed release
20.92 20.9.7
20.12 20.12.5
20.15 20.15.2

For leadership 🧭

Executive summary. A certificate validation flaw in Catalyst SD-WAN Manager’s Smart Licensing traffic could expose credentials used to connect to Cisco’s cloud services if that traffic is intercepted from a privileged network position. There’s no known exploitation and no direct device compromise, so this can be scheduled through normal patching rather than treated as an emergency.

Why it matters:

  • Only confidentiality is at risk (C:H/I:N/A:N) β€” an attacker who can intercept SD-WAN Manager’s internet-bound Smart Licensing traffic can read credentials the device uses to authenticate to Cisco cloud services.
  • No authentication to SD-WAN Manager itself is required; the attacker instead needs a privileged network position to intercept traffic, which raises the bar but doesn’t require any device-side foothold.
  • There are no workarounds, so any affected deployment configured for Cisco-hosted Smart Licensing stays exposed to interception until it’s upgraded.
  • Several releases (20.11.x, 20.13.x, 20.14.x) have reached End of Software Maintenance and have no direct fix, meaning affected devices on those trains require a full migration rather than a simple patch.

Now / Next / Later:

  • Now: Identify which Catalyst SD-WAN Manager instances are configured to connect to Cisco-hosted Smart Licensing and confirm their current release train.
  • Next: Upgrade to the fixed release for your train β€” 20.9.7, 20.12.5 or 20.15.2 β€” or migrate off 20.11.x, 20.13.x or 20.14.x, which have no direct fix; 20.16 is already unaffected.
  • Later: Once patched, rotate the Smart Licensing credentials on affected devices as a precaution, and factor End-of-Software-Maintenance status into future SD-WAN Manager upgrade planning so trains don’t linger without fixes available.

Source