Mandiant has published a technical breakdown of how threat actors exploited a critical vulnerability in Cisco Catalyst SD-WAN Manager, designated as CVE-2024-20445. The flaw resides in the web-based management interface, allowing unauthenticated remote attackers to gain root-level access to the underlying operating system. The exploit leveraged a path traversal vulnerability in the system's logging functionality, which permitted attackers to write files to restricted directories and bypass standard authentication protocols.
During the observation of live attacks, researchers identified that the intruders used this unauthorized file-writing capability to inject new user credentials into the system. By manipulating these files, attackers successfully created rogue root-level accounts that persisted on the affected SD-WAN instances. Once these accounts were active, the attackers could execute arbitrary commands with full administrative privileges, effectively compromising the integrity and security of the entire software-defined networking infrastructure.
The disclosure highlights the specific methods used to transition from an initial web interface vulnerability to full system takeover. Cisco has previously released patches for this vulnerability, and security investigators emphasize that the exploit did not require high levels of technical complexity once the specific entry point was identified. The research also tracks the post-exploitation activity, noting that the primary goal in several documented cases was the establishment of a foothold for potential lateral movement or long-term persistence within the target network.
For CIOs and IT directors, this development underscores the critical nature of securing software-defined infrastructure that manages high-level network traffic. Because SD-WAN managers serve as central control points, vulnerabilities that lead to root escalation require immediate patching and thorough auditing of existing administrative accounts to ensure no unauthorized credentials have been introduced during the window of exposure. Organizations utilizing these platforms should prioritize the updates provided by Cisco to mitigate these risks.
