← Back

CVE-2022-20716

nvd nist
Published: Apr 15, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper access control on files within the affected system. A local attacker could exploit this vulnerability by modifying certain files on the vulnerable device. If successful, the attacker could gain escalated privileges and take actions on the system with the privileges of the root user.

Affected (8)

7 products
Catalyst Sd Wan Manager
Sd Wan Solution
Sd Wan Vbond Orchestrator
Sd Wan Vedge Cloud
Sd Wan Vedge Router
Sd Wan Vsmart Controller Software
Sd Wan
Configuration A
6 vulnerable
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
From 18.4 to 20.6.1
From 20.7 to 20.7.1

Timeline

No history available yet.