CVE-2022-20775

Cisco SD-WAN Software Privilege Escalation Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
November 02, 2021
Published Date
September 30, 2022
Last Updated
March 02, 2026
Vendor
Cisco
Product
Cisco Catalyst SD-WAN, Cisco Catalyst SD-WAN Manager, Cisco SD-WAN vContainer, Cisco SD-WAN vEdge Cloud, Cisco SD-WAN vEdge Router
Description
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF
Tags
cisa

CVSS Scores

CVSS v3.1

7.8 - HIGH

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 11:08:34 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 11:08:34 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel