CVE-2022-20850: Cisco SD-WAN Arbitrary File Deletion Vulnerability
A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary file path information when using commands in the CLI of an affected device. A successful exploit could allow the attacker to delete arbitrary files from the file system of the affected device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20850?
CVE-2022-20850 is a vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software that could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device.
How can an attacker exploit CVE-2022-20850?
An attacker could exploit CVE-2022-20850 by leveraging insufficient input validation in order to delete arbitrary files from the file system of an affected device.
What is the severity of CVE-2022-20850?
CVE-2022-20850 has a severity rating of 7.1 (High).
Which software and devices are affected by CVE-2022-20850?
CVE-2022-20850 affects Cisco IOS XE SD-WAN Software, Cisco SD-WAN Software, Cisco SD-WAN vManage, Cisco SD-WAN vsmart Controller, and Cisco Sd-wan Vbond Orchestrator with specific versions.
How can I fix CVE-2022-20850?
To fix CVE-2022-20850, it is recommended to update to a version of the affected software that is not vulnerable and follow the guidance provided by Cisco.