cbcvebase.
CVE-2022-20775
published 2022-09-30

CVE-2022-20775: A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to…

PriorityP182high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-02-27
Exploited in the wild
EPSS
12.47%
95.7th percentile
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF

Affected

477 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocatalyst_sd-wan_manager< 20.6.320.6.3
ciscocatalyst_sd-wan_manager
ciscocatalyst_sd-wan_manager>= 20.7 < 20.7.220.7.2
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan
ciscocisco_catalyst_sd-wan

Detection & IOCsextracted from sources · hover to see the quote

path/var/log/
path/var/volatile/log/vdebug
path/var/volatile/log/sw_script_synccdb.log
snort
65938
snort
65958
  • Monitor SD-WAN logs for unexpected software version downgrades followed by reboots, which may indicate CVE-2022-20775 exploitation to gain root access before restoring the original version.
  • Alert on the log message 'Software upgrade not confirmed. Reverting to previous software version' as a potential indicator of deliberate version downgrade for privilege escalation.
  • Detect interactive root login events via the system notification log pattern: system-login-change severity-level:minor user-name:"root".
  • Audit /var/log/auth.log for 'Accepted publickey for vmanage-admin' entries from unknown IP addresses as an indicator of unauthorized SSH access.
  • Check for abnormally small (0/1/2 byte) or absent log files in /var/log/ (syslog, wtmp, lastlog, cli-history, bash_history) as evidence of post-exploitation log tampering.
  • Investigate control-connection-state-change log events for unexpected peer-type:vmanage entries, validating peer-system-ip and public-ip against known authorized infrastructure.
  • Look for presence of a cli-history file for a user that has no corresponding bash_history, which may indicate malicious account creation and cleanup activity.
  • Analyze /var/volatile/log/vdebug, /var/log/tmplog/vdebug, and /var/volatile/log/sw_script_synccdb.log specifically for forensic evidence of CVE-2022-20775 exploitation.
  • ·CVE-2022-20775 was exploited in the wild as part of a chained attack: threat actor first used CVE-2026-20127 to gain initial access, then downgraded software to exploit CVE-2022-20775 for root escalation, then restored the original version — making the downgrade/restore cycle itself a key detection signal rather than the vulnerability alone.
  • ·If a root account was compromised via CVE-2022-20775, Cisco and CISA advise deploying fresh installs rather than attempting to clean existing infrastructure, as persistence mechanisms may survive remediation.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_cisco7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.