CVE-2022-20775

9.5 CISA KEV

Cisco · SD-WAN

A path traversal vulnerability in the Cisco SD-WAN CLI allows an authenticated local attacker to execute arbitrary commands with root privileges.

Executive summary

Cisco SD-WAN is affected by a critical privilege escalation vulnerability that is currently being actively exploited in the wild.

Vulnerability

This vulnerability involves improper access controls on CLI commands, allowing an authenticated local attacker to perform path traversal. By executing a specially crafted command, an attacker can gain root-level access to the underlying system.

Business impact

The exploitation of this vulnerability poses a severe threat to network integrity, as it grants attackers full root-level control over critical SD-WAN infrastructure. With a CVSS score of 9.5, this flaw enables unauthorized access, potential data exfiltration, and the ability to pivot deeper into the corporate network. Given that threat actors are actively using this to establish persistence, the risk of total system compromise and operational disruption is extremely high.

Remediation

Immediate Action: Upgrade all affected components to the patched versions: 20.6.3, 20.7.1, 20.8.1, 20.9.1, 20.10.1, 20.11.1, or 20.12.1.

Proactive Monitoring: Audit system logs for unauthorized CLI command execution and monitor for unexpected administrative account activity or persistent connection attempts from internal nodes.

Compensating Controls: Restrict access to the device CLI to only essential personnel and enforce strict multi-factor authentication for all administrative sessions to minimize the risk of initial unauthorized access.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in various security research trackers.

Analyst recommendation

Due to the confirmed active exploitation and the critical severity of this vulnerability, organizations must treat this as a top-priority security event. Administrators should verify their versions against the provided list and apply the vendor-supplied patches immediately to prevent unauthorized root access and persistent system compromise.

More Cisco CVEs

Sources