12346-udp-pentesting-cisco-sd-wan-control-plane.md (4303B)
1 --- 2 title: "12346/udp - Pentesting Cisco Catalyst SD-WAN Control Plane" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/12346-udp-pentesting-cisco-sd-wan-control-plane.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/12346-udp-pentesting-cisco-sd-wan-control-plane.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 12346/udp - Pentesting Cisco Catalyst SD-WAN Control Plane 14 15 ## Basic Information 16 17 Cisco Catalyst SD-WAN controllers expose a **DTLS control-plane service on UDP/12346** (`vdaemon`). This service should be treated like a routing-adjacency surface: if an attacker can become an authenticated peer, they may be able to pivot into the overlay fabric.<sup>[[1]](#references)</sup> 18 19 `vdaemon` uses a **12-byte header** where the **high nibble** of `device_info` encodes the claimed device role: 20 21 | Role value | Claimed role | 22 | --- | --- | 23 | `1` | vEdge | 24 | `2` | vHub | 25 | `3` | vSmart | 26 | `4` | vBond | 27 | `5` | vManage | 28 | `6` | ZTP | 29 30 The DTLS handshake is not enough to authenticate a peer by itself. Peer trust is finalized later during control-plane bootstrap messages such as `CHALLENGE_ACK`.<sup>[[1]](#references)</sup> 31 32 **Default port:** 12346/udp 33 34 ```text 35 PORT STATE SERVICE 36 12346/udp open unknown 37 ``` 38 39 ## Enumeration 40 41 Discover the control-plane service and follow-on management ports: 42 43 ```bash 44 nmap -sU -p12346 <IP> 45 nmap -sT -p22,830 <IP> 46 ``` 47 48 If the host exposes TCP/830, check whether NETCONF over SSH is reachable: 49 50 ```bash 51 ssh -p 830 <user>@<IP> 52 ``` 53 54 ## Pentesting Cisco SD-WAN Control Plane 55 56 ### Pre-auth Role Confusion 57 58 `CHALLENGE_ACK` (**message type `9`**) is reachable before authentication because it is part of the control-plane bootstrap allowlist. In CVE-2026-20182, Rapid7 showed that `vbond_proc_challenge_ack()` verified some roles (`vEdge`, `vSmart`, `vManage`) but had no verification branch for claimed role `2` / vHub.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 59 60 Because the function later fell through to `peer->authenticated = 1`, an attacker could: 61 62 1. Complete DTLS with any certificate. 63 2. Send `CHALLENGE_ACK` with the high nibble of `device_info` set to `2`. 64 3. Send `Hello`. 65 4. Transition to an UP authenticated peer. 66 67 This is a useful bug pattern to hunt in proprietary control planes: attacker-controlled role selection, missing default-deny validation, and pre-auth handshake messages. 68 69 ### Post-auth Pivot 70 71 Once treated as an authenticated peer, the controller accepted `MSG_VMANAGE_TO_PEER` (**message type `14`**) and appended attacker-controlled data to `/home/vmanage-admin/.ssh/authorized_keys`.<sup>[[1]](#references)</sup> 72 73 This turns a control-plane foothold into persistent NETCONF over SSH access on TCP/830 as `vmanage-admin`. 74 75 ```bash 76 # Rapid7 module automating the vHub auth bypass and SSH key injection 77 msf6 > use auxiliary/admin/networking/cisco_sdwan_vhub_auth_bypass 78 msf6 auxiliary(cisco_sdwan_vhub_auth_bypass) > set RHOSTS <IP> 79 msf6 auxiliary(cisco_sdwan_vhub_auth_bypass) > run 80 81 # If the target accepts the injected key, pivot to NETCONF over SSH 82 ssh -i <loot_key.pem> vmanage-admin@<IP> -p 830 83 ``` 84 85 Review similar appliances for post-auth messages that write SSH keys, API tokens, trust bundles, or bootstrap secrets for privileged internal service accounts. 86 87 ## Detection 88 89 - Audit Internet-facing or cross-trust-boundary exposure of UDP/12346 and TCP/830. 90 - Inspect `/home/vmanage-admin/.ssh/authorized_keys` for unexpected appended keys after control-plane events. 91 - After gaining NETCONF, remember that configuration and state retrieval may be available even if a normal shell is not. 92 93 ## Shodan 94 95 - `port:12346` 96 - `port:830 "NETCONF"` 97 98 ## References 99 100 - [1] [Rapid7: CVE-2026-20182 - Critical authentication bypass in Cisco Catalyst SD-WAN Controller](https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/) 101 - [2] [Cisco Security Advisory: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW)