CVE-2022-20818
published 2022-09-30CVE-2022-20818: Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.60%
44.7th percentile
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_sd-wan_solution | — | — |
| cisco | sd-wan | < 20.9 | 20.9 |
| cisco | sd-wan | — | — |
| cisco | sd-wan_vbond_orchestrator | < 20.9 | 20.9 |
| cisco | sd-wan_vmanage | < 20.9 | 20.9 |
| cisco | sd-wan_vsmart_controller | < 20.9 | 20.9 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco SD-WAN Software Privilege Escalation Vulnerabilities
vendor_cisco·2022-09-28·CVSS 7.8
CVE-2022-20775 [HIGH] CWE-25 Cisco SD-WAN Software Privilege Escalation Vulnerabilities
Cisco SD-WAN Software Privilege Escalation Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges.
These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF
Cisco
Cisco SD-WAN Software Privilege Escalation Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2022-20818 Cisco SD-WAN Software Privilege Escalation Vulnerabilities
CVE-2022-20818: Cisco SD-WAN Software Privilege Escalation Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.1
CWE: CWE-25, CWE-282, CWE-25, CWE-282
Bug IDs: CSCwa52793, CSCwb54198
GHSA
GHSA-8whp-gj34-8pwr: Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges
ghsa_unreviewed·2022-10-01
CVE-2022-20818 [HIGH] CWE-22 GHSA-8whp-gj34-8pwr: Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-30
Published