Cybersecurity agencies including the National Cyber Security Centre are warning about the potential compromise of Cisco Catalyst SD-WAN, encouraging an immediate investigation into the globally-used network.
Malicious cyber threat actors are targeting Cisco Catalyst Software Defined Wide Area Networks (SD-WAN) used by organisations globally.
These actors are compromising SD-WANs to add a malicious rogue peer and then conduct a range of follow-on actions to achieve root access and maintain persistent access to the SD-WAN.
This cluster of cyber threat activity has targeted organisations using Cisco Catalyst SD-WANs globally.
A Hunt Guide has been prepared based on observations from various investigations which details tactics, techniques, and procedures (TTPs) leveraged by these malicious actors. The Hunt Guide aims to support network defenders to conduct detection and threat hunting activities and provides mitigation guidance to reduce the risk from the observed TTPs.
The Hunt Guide is being released and co-signed by a range of agencies, including those in Australia, Canada, New Zealand, the UK, and the US.
Cisco has released software updates for Cisco Catalyst SD-WAN Manager and Cisco Catalyst SD-WAN Controller.
Organisations employing Cisco Catalyst SD-WAN could be affected, and should follow the priority actions detailed below.
Cisco Catalyst SD-WANs that have management interfaces exposed to the internet are at most risk of compromise, the NCSC warns. These management interfaces must never be exposed to the internet.
Network defenders are urged to follow certain priority actions, including:
- Threat hunting for evidence of compromise detailed in the Hunt Guide.
- If you believe you have been compromised, collect artefacts from the device and, if you are in the UK, report it to the NCSC.
- Update to the appropriate fixed latest version of Cisco Catalyst SD-WAN Manager and Cisco Catalyst SD-WAN Controller as detailed in their respective advisories.
- Apply the Cisco Catalyst SD-WAN Hardening Guide.
- Perform continuous threat hunting activities.
To reduce the risks to any network, organisations are encouraged to take appropriate action based on the Cisco Catalyst SD-WAN Hardening Guide.
Recommended reading
- NCSC Warns Critical National Infrastructure to Strengthen Cyber Defences
- Turing Institute Develops AI Cyber Tools to Defend Critical National Infrastructure
- NCSC Updates Cyber Assessment Framework for Rising CNI Threats
Actions could include securing network perimeter controls, reconfiguring SD-WAN manager access, using pairwise keying on data plane security, limiting session timeouts to the shortest possible periods, and using a remote syslog server for logging.
The NCSC has said that any of its proposed mitigation or eviction measures are subject to change as new information becomes available and ongoing coordinated operated dictate.
Network defenders should ensure any actions taken in response to the Hunt Guide are compliant with local laws and regulations within the jurisdictions within which they operate.





