CVE-2022-20818: Cisco SD-WAN Software Privilege Escalation Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20818?
CVE-2022-20818 has been classified with a critical severity due to potential privilege escalation vulnerabilities.
How do I fix CVE-2022-20818?
To fix CVE-2022-20818, ensure that you upgrade to the latest version of Cisco SD-WAN Software beyond version 20.9.
Who is affected by CVE-2022-20818?
CVE-2022-20818 affects Cisco SD-WAN solutions including the vBond Orchestrator, vManage, and vSmart Controller running version 20.9 or earlier.
What could an attacker achieve by exploiting CVE-2022-20818?
An attacker exploiting CVE-2022-20818 could gain elevated privileges, potentially allowing unauthorized access to sensitive commands.
Is there a workaround for CVE-2022-20818?
Currently, Cisco has not provided any specific workarounds for CVE-2022-20818 aside from upgrading to secure versions.