V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-20775
CVE
High KEVConfirmedExploit available

Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. Thes…

CVSS
7.8
High
EPSS
0.12
p95
Published
2022-01-01
Updated
2026-02-25
Description

Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

Tags · CWE
KEV
CWE-25
Affected products
Catalyst_sd-wan_manager < 20.6.3Catalyst_sd-wan_manager 20.7–20.7.2Catalyst_sd-wan_managerSd-wan_vbond_orchestrator < 20.6.3Sd-wan_vbond_orchestrator 20.7–20.7.2Sd-wan_vbond_orchestratorSd-wan_vedge_cloud < 20.6.3Sd-wan_vedge_cloud 20.7–20.7.2Sd-wan_vedge_cloudSd-wan_vsmart_controller < 20.6.3Sd-wan_vsmart_controller 20.7–20.7.2Sd-wan_vsmart_controller
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2022-01-01
Published
2026-02-25
Added to KEV
2026-02-25
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.125 · p95
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2022-20775
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
Affected products
ProductVendorStatus
catalyst_sd-wan_manager*Exploited
sd-wan*Exploited
sd-wan_vbond_orchestrator*Exploited
sd-wan_vedge_cloud*Exploited
sd-wan_vsmart_controller*Exploited
Source databases
CVE
Related vulnerabilities