CVE-2022-20775
9.5 CISA KEVCisco · SD-WAN
A path traversal vulnerability in the Cisco SD-WAN CLI allows an authenticated local attacker to execute arbitrary commands with root privileges.
Executive summary
Cisco SD-WAN is affected by a critical privilege escalation vulnerability that is currently being actively exploited in the wild.
Vulnerability
This vulnerability involves improper access controls on CLI commands, allowing an authenticated local attacker to perform path traversal. By executing a specially crafted command, an attacker can gain root-level access to the underlying system.
Business impact
The exploitation of this vulnerability poses a severe threat to network integrity, as it grants attackers full root-level control over critical SD-WAN infrastructure. With a CVSS score of 9.5, this flaw enables unauthorized access, potential data exfiltration, and the ability to pivot deeper into the corporate network. Given that threat actors are actively using this to establish persistence, the risk of total system compromise and operational disruption is extremely high.
Remediation
Immediate Action: Upgrade all affected components to the patched versions: 20.6.3, 20.7.1, 20.8.1, 20.9.1, 20.10.1, 20.11.1, or 20.12.1.
Proactive Monitoring: Audit system logs for unauthorized CLI command execution and monitor for unexpected administrative account activity or persistent connection attempts from internal nodes.
Compensating Controls: Restrict access to the device CLI to only essential personnel and enforce strict multi-factor authentication for all administrative sessions to minimize the risk of initial unauthorized access.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in various security research trackers.
Analyst recommendation
Due to the confirmed active exploitation and the critical severity of this vulnerability, organizations must treat this as a top-priority security event. Administrators should verify their versions against the provided list and apply the vendor-supplied patches immediately to prevent unauthorized root access and persistent system compromise.