Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-20716


A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper access control on files within the affected system. A local attacker could exploit this vulnerability by modifying certain files on the vulnerable device. If successful, the attacker could gain escalated privileges and take actions on the system with the privileges of the root user.


Published

2022-04-15T15:15:13.063

Last Modified

2024-11-21T06:43:23.910

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco catalyst_sd-wan_manager - Yes
Application cisco sd-wan_solution - Yes
Application cisco sd-wan_vbond_orchestrator - Yes
Application cisco sd-wan_vedge_cloud - Yes
Application cisco sd-wan_vedge_router - Yes
Application cisco sd-wan_vsmart_controller_software - Yes
Application cisco sd-wan < 20.6.1 Yes
Application cisco sd-wan < 20.7.1 Yes

References