CVE-2022-20775
Description
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges.
This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
StableCommon Consequences
Applicable Platforms
Path Traversal: '/../filedir'
IncompleteCommon Consequences
Applicable Platforms
Catalyst Sd-Wan Manager by Cisco
cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.8:*:*:*:*:*:*:*
Sd-Wan Vedge Cloud by Cisco
cpe:2.3:a:cisco:sd-wan_vedge_cloud:20.8:*:*:*:*:*:*:*
Catalyst Sd-Wan Manager by Cisco
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
Sd-Wan Vedge Cloud by Cisco
cpe:2.3:a:cisco:sd-wan_vedge_cloud:*:*:*:*:*:*:*:*
Catalyst Sd-Wan Manager by Cisco
cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:*
Sd-Wan Vedge Cloud by Cisco
cpe:2.3:a:cisco:sd-wan_vedge_cloud:*:*:*:*:*:*:*:*
Sd-Wan Vsmart Controller by Cisco
cpe:2.3:a:cisco:sd-wan_vsmart_controller:*:*:*:*:*:*:*:*
Sd-Wan by Cisco
cpe:2.3:a:cisco:sd-wan:20.8:*:*:*:*:*:*:*
Sd-Wan by Cisco
cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:*
Sd-Wan Vbond Orchestrator by Cisco
cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:20.8:*:*:*:*:*:*:*
Sd-Wan Vbond Orchestrator by Cisco
cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:*:*:*:*:*:*:*:*
Sd-Wan Vbond Orchestrator by Cisco
cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:*:*:*:*:*:*:*:*
Sd-Wan Vsmart Controller by Cisco
cpe:2.3:a:cisco:sd-wan_vsmart_controller:20.8:*:*:*:*:*:*:*
Sd-Wan by Cisco
cpe:2.3:a:cisco:sd-wan:*:*:*:*:*:*:*:*
Sd-Wan Vsmart Controller by Cisco
cpe:2.3:a:cisco:sd-wan_vsmart_controller:*:*:*:*:*:*:*:*