Name:Cisco SD-WAN - Arbitrary File Overwrite Exploitation Activity id:2f3862c6-45ff-4a02-9bd4-7e25c209fcd9 version:3 date:None author:Nasreddine Bencherchali, Splunk status:production type:TTP Description:This analytic detects a exploitation activity attempts of targeting Cisco Catalyst SD-WAN Manager.
It leverages the "serviceproxy_access.log" and identifies source-host combinations that perform all key stages of the exploitation as reported in public POCs in a short period: authentication/config collection (`.dca`), upload actions (`uploadAck`), and payload-style access (`.gz/*`).
The behavior can indicate attempted exploitation activity associated with Cisco Catalyst SD-WAN Manager vulnerabilities CVE-2026-20122 (Arbitrary File Overwrite) and CVE-2026-20128 (Information Disclosure).
Data_source:
| search ( ( http_method="POST" uri IN ( "*/dataservice/smartLicensing/uploadAck*" ) ) OR ( http_method="GET" uri="*/reports/data/opt/data/containers/config/data-collection-agent/.dca*" ) OR (uri="*.gz/*") )
| bin _time span=1m | stats dc(uri_sequence_steps) as unique_uri_sequence_steps values(uri) as uri values(http_method) as http_method values(http_user_agent) as http_user_agent min(_time) as firstTime max(_time) as lastTime by src dest _time
how_to_implement:This detection requires Cisco SD-WAN Manager Envoy access logs to be ingested into Splunk.
These logs are located in "/var/log/nms/containers/service-proxy/serviceproxy-access.log".
known_false_positives:No false positives have been identified at this time.
References: -https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v -https://github.com/zerozenxlabs/CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE drilldown_searches: name:'View the detection results for - "$src$"' search:'%original_detection_search% | search src = "$src$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$src$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Cisco Catalyst SD-WAN Analytics']