CVE-2022-20775High KEVConfirmedExploit available
CVE
CVE
National Vulnerability Database
NVD is the U.S. government repository of standards-based vulnerability management data, built on top of the MITRE CVE list. Every record includes CPE applicability statements, CVSS v2 and v3.x base scores, CWE mappings and cross-references to advisories.
Region
US
Updates
15 min
License
Public Domain
Comprehensive catalog of publicly disclosed vulnerabilities with CPE matches, CVSS scoring and reference URLs. De-facto standard for cross-vendor correlation.
https://nvd.nist.gov →Share link
Anyone with the link can open this vulnerability.
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. Thes…
CVSS
7.8
High
EPSS
0.12
p95
Published
2022-01-01
Updated
2026-02-25
Description
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Tags · CWE
KEV
CWE-25
CWE-25VariantIncomplete
Path Traversal: '/../filedir'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "/../" sequences that can resolve to a location that is outside of that directory.
https://cwe.mitre.org/data/definitions/25.html →Open in CWE collection →Affected products
Catalyst_sd-wan_manager < 20.6.3Catalyst_sd-wan_manager 20.7–20.7.2Catalyst_sd-wan_managerSd-wan_vbond_orchestrator < 20.6.3Sd-wan_vbond_orchestrator 20.7–20.7.2Sd-wan_vbond_orchestratorSd-wan_vedge_cloud < 20.6.3Sd-wan_vedge_cloud 20.7–20.7.2Sd-wan_vedge_cloudSd-wan_vsmart_controller < 20.6.3Sd-wan_vsmart_controller 20.7–20.7.2Sd-wan_vsmart_controller
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2022-01-01
Published
2026-02-25
Added to KEV
2026-02-25
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.125 · p95
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2022-20775
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Affected products
| Product | Vendor | Status |
|---|---|---|
| catalyst_sd-wan_manager | * | Exploited |
| sd-wan | * | Exploited |
| sd-wan_vbond_orchestrator | * | Exploited |
| sd-wan_vedge_cloud | * | Exploited |
| sd-wan_vsmart_controller | * | Exploited |
Source databases
CVE
CVE
National Vulnerability Database
NVD is the U.S. government repository of standards-based vulnerability management data, built on top of the MITRE CVE list. Every record includes CPE applicability statements, CVSS v2 and v3.x base scores, CWE mappings and cross-references to advisories.
Region
US
Updates
15 min
License
Public Domain
Comprehensive catalog of publicly disclosed vulnerabilities with CPE matches, CVSS scoring and reference URLs. De-facto standard for cross-vendor correlation.
https://nvd.nist.gov →Related vulnerabilities