Lucene search

K
cve[email protected]CVE-2022-20818
HistorySep 30, 2022 - 7:15 p.m.

CVE-2022-20818

2022-09-3019:15:11
CWE-25
CWE-22
web.nvd.nist.gov
42
9
cve
2022
20818
cisco
sd-wan
software
cli
vulnerabilities
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

10.0%

Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

Affected configurations

NVD
Node
ciscosd-wan_vbond_orchestratorRange<20.9
OR
ciscosd-wan_vmanageRange<20.9
OR
ciscosd-wan_vsmart_controllerRange<20.9
Node
ciscocatalyst_8000v_edgeMatch-
OR
ciscocatalyst_cg418-eMatch-
OR
ciscocatalyst_cg522-eMatch-
OR
cisco1100-4g_integrated_services_routerMatch-
OR
cisco1100-4p_integrated_services_routerMatch-
OR
cisco1100-6g_integrated_services_routerMatch-
OR
cisco1100-8p_integrated_services_routerMatch-
OR
cisco1100_integrated_services_routerMatch-
OR
cisco1101-4p_integrated_services_routerMatch-
OR
cisco1101_integrated_services_routerMatch-
OR
cisco1109-2p_integrated_services_routerMatch-
OR
cisco1109-4p_integrated_services_routerMatch-
OR
cisco1109_integrated_services_routerMatch-
OR
cisco1111x-8p_integrated_services_routerMatch-
OR
cisco1111x_integrated_services_routerMatch-
OR
cisco111x_integrated_services_routerMatch-
OR
cisco1120_integrated_services_routerMatch-
OR
cisco1131_integrated_services_routerMatch-
OR
cisco1160_integrated_services_routerMatch-
OR
cisco4000_integrated_services_routerMatch-
OR
cisco4221_integrated_services_routerMatch-
OR
cisco4321\/k9-rf_integrated_services_routerMatch-
OR
cisco4321\/k9-ws_integrated_services_routerMatch-
OR
cisco4321\/k9_integrated_services_routerMatch-
OR
cisco4321_integrated_services_routerMatch-
OR
cisco4331\/k9-rf_integrated_services_routerMatch-
OR
cisco4331\/k9-ws_integrated_services_routerMatch-
OR
cisco4331\/k9_integrated_services_routerMatch-
OR
cisco4331_integrated_services_routerMatch-
OR
cisco4351\/k9-rf_integrated_services_routerMatch-
OR
cisco4351\/k9-ws_integrated_services_routerMatch-
OR
cisco4351\/k9_integrated_services_routerMatch-
OR
cisco4351_integrated_services_routerMatch-
OR
cisco4431_integrated_services_routerMatch-
OR
cisco4451-x_integrated_services_routerMatch-
OR
cisco4451_integrated_services_routerMatch-
OR
cisco4461_integrated_services_routerMatch-
OR
cisco8101-32fhMatch-
OR
cisco8101-32hMatch-
OR
cisco8102-64hMatch-
OR
cisco8201Match-
OR
cisco8201-32fhMatch-
OR
cisco8202Match-
OR
cisco8804Match-
OR
cisco8808Match-
OR
cisco8812Match-
OR
cisco8818Match-
OR
cisco8831Match-
OR
ciscoasr_1000Match-
OR
ciscoasr_1000-xMatch-
OR
ciscoasr_1001Match-
OR
ciscoasr_1001-hxMatch-
OR
ciscoasr_1001-hx_rMatch-
OR
ciscoasr_1001-xMatch-
OR
ciscoasr_1001-x_rMatch-
OR
ciscoasr_1002Match-
OR
ciscoasr_1002-hxMatch-
OR
ciscoasr_1002-hx_rMatch-
OR
ciscoasr_1002-xMatch-
OR
ciscoasr_1002-x_rMatch-
OR
ciscoasr_1004Match-
OR
ciscoasr_1006Match-
OR
ciscoasr_1006-xMatch-
OR
ciscoasr_1009-xMatch-
OR
ciscoasr_1013Match-
OR
ciscoasr_1023Match-
OR
ciscocatalyst_8200Match-
OR
ciscocatalyst_8300Match-
OR
ciscocatalyst_8300-1n1s-4t2xMatch-
OR
ciscocatalyst_8300-1n1s-6tMatch-
OR
ciscocatalyst_8300-2n2s-4t2xMatch-
OR
ciscocatalyst_8300-2n2s-6tMatch-
OR
ciscocatalyst_8500Match-
OR
ciscocatalyst_8500-4qcMatch-
OR
ciscocatalyst_8500lMatch-
OR
ciscocatalyst_8510csrMatch-
OR
ciscocatalyst_8510msrMatch-
OR
ciscocatalyst_8540csrMatch-
OR
ciscocatalyst_8540msrMatch-
AND
ciscosd-wanRange<20.9

CNA Affected

[
  {
    "product": "Cisco SD-WAN Solution ",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

Social References

More

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

10.0%

Related for CVE-2022-20818