Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-20850


A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary file path information when using commands in the CLI of an affected device. A successful exploit could allow the attacker to delete arbitrary files from the file system of the affected device.


Published

2022-09-30T19:15:12.543

Last Modified

2024-11-21T06:43:41.000

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco sd-wan_vbond_orchestrator < 18.4.5 Yes
Application cisco sd-wan_vmanage < 18.4.5 Yes
Application cisco sd-wan_vsmart_controller < 18.4.5 Yes
Operating System cisco ios_xe_sd-wan < 16.10.1 Yes
Application cisco sd-wan < 18.4.5 Yes
Hardware cisco 1100-4g_integrated_services_router - No
Hardware cisco 1100-6g_integrated_services_router - No
Hardware cisco 1100_integrated_services_router - No
Hardware cisco vedge_100 - No
Hardware cisco vedge_1000 - No
Hardware cisco vedge_100b - No
Hardware cisco vedge_100m - No
Hardware cisco vedge_2000 - No
Hardware cisco vedge_5000 - No

References