daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

12346-udp-pentesting-cisco-sd-wan-control-plane.md (4303B)


      1 ---
      2 title: "12346/udp - Pentesting Cisco Catalyst SD-WAN Control Plane"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/12346-udp-pentesting-cisco-sd-wan-control-plane.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/12346-udp-pentesting-cisco-sd-wan-control-plane.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 12346/udp - Pentesting Cisco Catalyst SD-WAN Control Plane
     14 
     15 ## Basic Information
     16 
     17 Cisco Catalyst SD-WAN controllers expose a **DTLS control-plane service on UDP/12346** (`vdaemon`). This service should be treated like a routing-adjacency surface: if an attacker can become an authenticated peer, they may be able to pivot into the overlay fabric.<sup>[[1]](#references)</sup>
     18 
     19 `vdaemon` uses a **12-byte header** where the **high nibble** of `device_info` encodes the claimed device role:
     20 
     21 | Role value | Claimed role |
     22 | --- | --- |
     23 | `1` | vEdge |
     24 | `2` | vHub |
     25 | `3` | vSmart |
     26 | `4` | vBond |
     27 | `5` | vManage |
     28 | `6` | ZTP |
     29 
     30 The DTLS handshake is not enough to authenticate a peer by itself. Peer trust is finalized later during control-plane bootstrap messages such as `CHALLENGE_ACK`.<sup>[[1]](#references)</sup>
     31 
     32 **Default port:** 12346/udp
     33 
     34 ```text
     35 PORT      STATE SERVICE
     36 12346/udp open  unknown
     37 ```
     38 
     39 ## Enumeration
     40 
     41 Discover the control-plane service and follow-on management ports:
     42 
     43 ```bash
     44 nmap -sU -p12346 <IP>
     45 nmap -sT -p22,830 <IP>
     46 ```
     47 
     48 If the host exposes TCP/830, check whether NETCONF over SSH is reachable:
     49 
     50 ```bash
     51 ssh -p 830 <user>@<IP>
     52 ```
     53 
     54 ## Pentesting Cisco SD-WAN Control Plane
     55 
     56 ### Pre-auth Role Confusion
     57 
     58 `CHALLENGE_ACK` (**message type `9`**) is reachable before authentication because it is part of the control-plane bootstrap allowlist. In CVE-2026-20182, Rapid7 showed that `vbond_proc_challenge_ack()` verified some roles (`vEdge`, `vSmart`, `vManage`) but had no verification branch for claimed role `2` / vHub.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     59 
     60 Because the function later fell through to `peer->authenticated = 1`, an attacker could:
     61 
     62 1. Complete DTLS with any certificate.
     63 2. Send `CHALLENGE_ACK` with the high nibble of `device_info` set to `2`.
     64 3. Send `Hello`.
     65 4. Transition to an UP authenticated peer.
     66 
     67 This is a useful bug pattern to hunt in proprietary control planes: attacker-controlled role selection, missing default-deny validation, and pre-auth handshake messages.
     68 
     69 ### Post-auth Pivot
     70 
     71 Once treated as an authenticated peer, the controller accepted `MSG_VMANAGE_TO_PEER` (**message type `14`**) and appended attacker-controlled data to `/home/vmanage-admin/.ssh/authorized_keys`.<sup>[[1]](#references)</sup>
     72 
     73 This turns a control-plane foothold into persistent NETCONF over SSH access on TCP/830 as `vmanage-admin`.
     74 
     75 ```bash
     76 # Rapid7 module automating the vHub auth bypass and SSH key injection
     77 msf6 > use auxiliary/admin/networking/cisco_sdwan_vhub_auth_bypass
     78 msf6 auxiliary(cisco_sdwan_vhub_auth_bypass) > set RHOSTS <IP>
     79 msf6 auxiliary(cisco_sdwan_vhub_auth_bypass) > run
     80 
     81 # If the target accepts the injected key, pivot to NETCONF over SSH
     82 ssh -i <loot_key.pem> vmanage-admin@<IP> -p 830
     83 ```
     84 
     85 Review similar appliances for post-auth messages that write SSH keys, API tokens, trust bundles, or bootstrap secrets for privileged internal service accounts.
     86 
     87 ## Detection
     88 
     89 - Audit Internet-facing or cross-trust-boundary exposure of UDP/12346 and TCP/830.
     90 - Inspect `/home/vmanage-admin/.ssh/authorized_keys` for unexpected appended keys after control-plane events.
     91 - After gaining NETCONF, remember that configuration and state retrieval may be available even if a normal shell is not.
     92 
     93 ## Shodan
     94 
     95 - `port:12346`
     96 - `port:830 "NETCONF"`
     97 
     98 ## References
     99 
    100 - [1] [Rapid7: CVE-2026-20182 - Critical authentication bypass in Cisco Catalyst SD-WAN Controller](https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/)
    101 - [2] [Cisco Security Advisory: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW)