services / Azure / Virtual WAN
A Virtual WAN is the top-level Azure networking construct that aggregates and interconnects virtual hubs, VNets, site-to-site/point-to-site VPN, and ExpressRoute connectivity into a managed SD-WAN backbone.
Acts as the connectivity fabric for a single organizational network function; compromise affects routing and reachability across all attached hubs and sites.
Microsoft.Network/virtualWans/generateVpnProfile/action
Generates a downloadable point-to-site VPN client profile containing certificate/credential material that lets an attacker authenticate and tunnel directly into the WAN's private network.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security