CVE-2022-20930: Cisco SD-WAN Software Arbitrary File Corruption Vulnerability
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary commands that are executed as the root user account. A successful exploit could allow the attacker to overwrite arbitrary system files, which could result in a denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-20930.
What is the severity of CVE-2022-20930?
The severity of CVE-2022-20930 is medium with a CVSS score of 6.7.
How does CVE-2022-20930 occur?
CVE-2022-20930 occurs due to insufficient input validation in the CLI of Cisco SD-WAN Software.
Who can exploit CVE-2022-20930?
An authenticated local attacker can exploit CVE-2022-20930.
How can CVE-2022-20930 be fixed?
Apply the necessary updates provided by Cisco to fix CVE-2022-20930.