CVE-2022-20775

Modified
Published: 30 Sept 2022, 18:45
Last modified:25 Feb 2026, 17:56

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
0.23% LOW
0% probability +0.10%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

30 Sept 2022, 18:45
Published
Vulnerability first disclosed
25 Feb 2026, 00:00
Added to CISA KEV
Cisco SD-WAN Path Traversal Vulnerability
25 Feb 2026, 17:56
Last Modified
Vulnerability information updated
27 Feb 2026, 00:00
CISA Remediation Due
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Description

Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.23% Percentile: 46%

Techniques & Countermeasures

  • CWE-25Path Traversal: '/../filedir'

    The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "/../" sequences that can resolve to a location that is outside of that directory.

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • ciscocatalyst_sd-wan_manager

    ≥ 20.6, < 20.6.3 | ≥ 20.7, < 20.7.2 | 20.8

  • ciscocisco sd-wan solution

    n/a

  • ciscosd-wan

    ≥ 20.6, < 20.6.3 | ≥ 20.7, < 20.7.2 | 20.8

  • ciscosd-wan_vbond_orchestrator

    ≥ 20.6, < 20.6.3 | ≥ 20.7, < 20.7.2 | 20.8

  • ciscosd-wan_vsmart_controller

    ≥ 20.6, < 20.6.3 | ≥ 20.7, < 20.7.2 | 20.8

References (3)