CVE-2022-20775 is a high-severity vulnerability in the Cisco SD-WAN Software CLI, allowing an authenticated, local attacker to gain elevated privileges due to improper access controls. With a CVSS score of 7.8, this flaw enables an attacker with low privileges to execute arbitrary commands as the root user, leading to high impact across confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its presence on the CISA KEV catalog and Hot List, and has garnered significant community and media attention, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.6.3CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
>= 20.7, < 20.7.2CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:*:*:*:*:*:*:*:* | ||
20.8CPE matchmatch criteria | cpe:2.3:a:cisco:catalyst_sd-wan_manager:20.8:*:*:*:*:*:*:* | ||
< 20.6.3CPE matchmatch criteria | cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:*:*:*:*:*:*:*:* | ||
>= 20.7, < 20.7.2CPE matchmatch criteria | cpe:2.3:a:cisco:sd-wan_vbond_orchestrator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.