CVE-2022-20716
Cisco SD-WAN Solution Improper Access Control Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper access control on files within the affected system. A local attacker could exploit this vulnerability by modifying certain files on the vulnerable device. If successful, the attacker could gain escalated privileges and take actions on the system with the privileges of the root user.
Una vulnerabilidad en la CLI del software Cisco SD-WAN podría permitir a un atacante local autenticado alcanzar altos privilegios. Esta vulnerabilidad es debido a un control de acceso inapropiado en los archivos del sistema afectado. Un atacante local podría explotar esta vulnerabilidad al modificar determinados archivos en el dispositivo vulnerable. Si es exitoso, el atacante podría alcanzar privilegios escalados y realizar acciones en el sistema con privilegios de usuario root
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2021-11-02 CVE Reserved
- 2022-04-15 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Catalyst Sd-wan Manager Search vendor "Cisco" for product "Catalyst Sd-wan Manager" | - | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Solution Search vendor "Cisco" for product "Sd-wan Solution" | - | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Vbond Orchestrator Search vendor "Cisco" for product "Sd-wan Vbond Orchestrator" | - | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Vedge Cloud Search vendor "Cisco" for product "Sd-wan Vedge Cloud" | - | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Vedge Router Search vendor "Cisco" for product "Sd-wan Vedge Router" | - | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Vsmart Controller Software Search vendor "Cisco" for product "Sd-wan Vsmart Controller Software" | - | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Search vendor "Cisco" for product "Sd-wan" | >= 18.4 < 20.6.1 Search vendor "Cisco" for product "Sd-wan" and version " >= 18.4 < 20.6.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Sd-wan Search vendor "Cisco" for product "Sd-wan" | >= 20.7 < 20.7.1 Search vendor "Cisco" for product "Sd-wan" and version " >= 20.7 < 20.7.1" | - |
Affected
|