CVE-2022-20775: Cisco SD-WAN Path Traversal Vulnerability
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF
Other sources
Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
— CISA
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Assess exposure and mitigate per CISA guidance: follow CISA Emergency Directive 26-03 and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices. For cloud services, adhere to BOD 22-01; if required mitigations are not available, discontinue use of the product.
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20775?
CVE-2022-20775 has been rated as high severity due to its potential to allow authenticated local attackers to gain elevated privileges.
How do I fix CVE-2022-20775?
To fix CVE-2022-20775, apply the latest software updates provided by Cisco for the affected SD-WAN software versions.
Which Cisco products are affected by CVE-2022-20775?
CVE-2022-20775 affects Cisco Catalyst SD-WAN Manager, Cisco vBond Orchestrator, and Cisco vSmart Controller versions between 20.6 and 20.8.
What type of vulnerability is CVE-2022-20775?
CVE-2022-20775 is an access control vulnerability that allows local attackers to exploit the CLI of Cisco SD-WAN software.
What are the potential consequences of exploiting CVE-2022-20775?
Exploiting CVE-2022-20775 can lead to unauthorized command execution and privileged access for attackers within the system.