CVE-2022-20775
Published on: Not Yet Published
Last Modified on: 11/10/2022 03:50:00 AM UTC
CVE-2022-20775 - advisory for cisco-sa-sd-wan-priv-E6e8tEdF
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of 8101-32fh from Cisco contain the following vulnerability:
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
- CVE-2022-20775 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco SD-WAN Solution version n/a
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Path Traversal in SD-WAN vEdge (x86 and mips64) routers (CVE-2022-20775) · Advisory · orangecertcc/security-research · GitHub | github.com text/html |
![]() |
No Description Provided | tools.cisco.com text/html |
![]() |
Related QID Numbers
- 317224 Cisco SD-WAN Software Privilege Escalation Vulnerability (cisco-sa-sd-wan-priv-E6e8tEdF)
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Cisco | 8101-32fh | - | All | All | All |
Hardware
| Cisco | 8101-32h | - | All | All | All |
Hardware
| Cisco | 8102-64h | - | All | All | All |
Hardware
| Cisco | 8201 | - | All | All | All |
Hardware
| Cisco | 8201-32fh | - | All | All | All |
Hardware
| Cisco | 8202 | - | All | All | All |
Hardware
| Cisco | 8804 | - | All | All | All |
Hardware
| Cisco | 8808 | - | All | All | All |
Hardware
| Cisco | 8812 | - | All | All | All |
Hardware
| Cisco | 8818 | - | All | All | All |
Hardware
| Cisco | 8831 | - | All | All | All |
Hardware
| Cisco | Asr 1000 | - | All | All | All |
Hardware
| Cisco | Asr 1000-x | - | All | All | All |
Hardware
| Cisco | Asr 1001 | - | All | All | All |
Hardware
| Cisco | Asr 1001-hx | - | All | All | All |
Hardware
| Cisco | Asr 1001-hx R | - | All | All | All |
Hardware
| Cisco | Asr 1001-x | - | All | All | All |
Hardware
| Cisco | Asr 1001-x R | - | All | All | All |
Hardware
| Cisco | Asr 1002 | - | All | All | All |
Hardware
| Cisco | Asr 1002-hx | - | All | All | All |
Hardware
| Cisco | Asr 1002-hx R | - | All | All | All |
Hardware
| Cisco | Asr 1002-x | - | All | All | All |
Hardware
| Cisco | Asr 1002-x R | - | All | All | All |
Hardware
| Cisco | Asr 1004 | - | All | All | All |
Hardware
| Cisco | Asr 1006 | - | All | All | All |
Hardware
| Cisco | Asr 1006-x | - | All | All | All |
Hardware
| Cisco | Asr 1009-x | - | All | All | All |
Hardware
| Cisco | Asr 1013 | - | All | All | All |
Hardware
| Cisco | Asr 1023 | - | All | All | All |
Application | Cisco | Catalyst 8000v Edge | - | All | All | All |
Hardware
| Cisco | Catalyst 8200 | - | All | All | All |
Hardware
| Cisco | Catalyst 8300 | - | All | All | All |
Hardware
| Cisco | Catalyst 8300-1n1s-4t2x | - | All | All | All |
Hardware
| Cisco | Catalyst 8300-1n1s-6t | - | All | All | All |
Hardware
| Cisco | Catalyst 8300-2n2s-4t2x | - | All | All | All |
Hardware
| Cisco | Catalyst 8300-2n2s-6t | - | All | All | All |
Hardware
| Cisco | Catalyst 8500 | - | All | All | All |
Hardware
| Cisco | Catalyst 8500-4qc | - | All | All | All |
Hardware
| Cisco | Catalyst 8500l | - | All | All | All |
Hardware
| Cisco | Catalyst 8510csr | - | All | All | All |
Hardware
| Cisco | Catalyst 8510msr | - | All | All | All |
Hardware
| Cisco | Catalyst 8540csr | - | All | All | All |
Hardware
| Cisco | Catalyst 8540msr | - | All | All | All |
Application | Cisco | Catalyst Cg418-e | - | All | All | All |
Application | Cisco | Catalyst Cg522-e | - | All | All | All |
Hardware
| Cisco | Isr4321/k9 | - | All | All | All |
Hardware
| Cisco | Isr4321/k9-rf | - | All | All | All |
Hardware
| Cisco | Isr4321/k9-ws | - | All | All | All |
Hardware
| Cisco | Isr4331/k9 | - | All | All | All |
Hardware
| Cisco | Isr4331/k9-rf | - | All | All | All |
Hardware
| Cisco | Isr4331/k9-ws | - | All | All | All |
Hardware
| Cisco | Isr4351/k9 | - | All | All | All |
Hardware
| Cisco | Isr4351/k9-rf | - | All | All | All |
Hardware
| Cisco | Isr4351/k9-ws | - | All | All | All |
Hardware
| Cisco | Isr 1100 | - | All | All | All |
Hardware
| Cisco | Isr 1100-4g | - | All | All | All |
Hardware
| Cisco | Isr 1100-4p | - | All | All | All |
Hardware
| Cisco | Isr 1100-6g | - | All | All | All |
Hardware
| Cisco | Isr 1100-8p | - | All | All | All |
Hardware
| Cisco | Isr 1101 | - | All | All | All |
Hardware
| Cisco | Isr 1101-4p | - | All | All | All |
Hardware
| Cisco | Isr 1109 | - | All | All | All |
Hardware
| Cisco | Isr 1109-2p | - | All | All | All |
Hardware
| Cisco | Isr 1109-4p | - | All | All | All |
Hardware
| Cisco | Isr 1111x | - | All | All | All |
Hardware
| Cisco | Isr 1111x-8p | - | All | All | All |
Hardware
| Cisco | Isr 111x | - | All | All | All |
Hardware
| Cisco | Isr 1120 | - | All | All | All |
Hardware
| Cisco | Isr 1131 | - | All | All | All |
Hardware
| Cisco | Isr 1160 | - | All | All | All |
Hardware
| Cisco | Isr 4000 | - | All | All | All |
Hardware
| Cisco | Isr 4221 | - | All | All | All |
Hardware
| Cisco | Isr 4321 | - | All | All | All |
Hardware
| Cisco | Isr 4331 | - | All | All | All |
Hardware
| Cisco | Isr 4351 | - | All | All | All |
Hardware
| Cisco | Isr 4431 | - | All | All | All |
Hardware
| Cisco | Isr 4451 | - | All | All | All |
Hardware
| Cisco | Isr 4451-x | - | All | All | All |
Hardware
| Cisco | Isr 4461 | - | All | All | All |
Application | Cisco | Sd-wan | All | All | All | All |
Application | Cisco | Sd-wan | 20.8 | All | All | All |
Application | Cisco | Sd-wan Vbond Orchestrator | All | All | All | All |
Application | Cisco | Sd-wan Vbond Orchestrator | 20.8 | All | All | All |
Application | Cisco | Sd-wan Vmanage | All | All | All | All |
Application | Cisco | Sd-wan Vmanage | 20.8 | All | All | All |
Application | Cisco | Sd-wan Vsmart Controller | All | All | All | All |
Application | Cisco | Sd-wan Vsmart Controller | 20.8 | All | All | All |
- cpe:2.3:h:cisco:8101-32fh:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:8101-32h:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:8102-64h:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:8201:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:8201-32fh:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:8202:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:8804:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:8808:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:8812:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:8818:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:8831:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1000:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1000-x:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1001:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1001-hx:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1001-hx_r:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1001-x:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1001-x_r:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1002:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1002-hx:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1002-hx_r:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1002-x:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1002-x_r:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1004:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1006:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1006-x:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1009-x:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1013:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:asr_1023:-:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:catalyst_8000v_edge:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8200:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8300:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8300-1n1s-4t2x:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8300-1n1s-6t:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8300-2n2s-4t2x:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8300-2n2s-6t:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8500:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8500-4qc:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8500l:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8510csr:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8510msr:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8540csr:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:catalyst_8540msr:-:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:catalyst_cg418-e:-:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:catalyst_cg522-e:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr4321\/k9:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr4321\/k9-rf:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr4321\/k9-ws:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr4331\/k9:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr4331\/k9-rf:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr4331\/k9-ws:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr4351\/k9:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr4351\/k9-rf:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr4351\/k9-ws:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1100:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1100-4g:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1100-4p:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1100-6g:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1100-8p:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1101:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1101-4p:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1109:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1109-2p:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1109-4p:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1111x:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1111x-8p:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_111x:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1120:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1131:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_1160:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_4000:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_4221:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_4321:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_4331:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_4351:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_4431:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_4451:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_4451-x:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:isr_4461:-:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sd-wan:20.8:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:20.8:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sd-wan_vmanage:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sd-wan_vmanage:20.8:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sd-wan_vsmart_controller:*:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:sd-wan_vsmart_controller:20.8:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-20775 : Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local a… twitter.com/i/web/status/1… | 2022-09-30 18:54:42 |
![]() |
CVE-2022-20775 | 2022-09-30 19:38:35 |