These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
The two vulnerabilities are CVE-2022-20775 and CVE-2022-20818, which have a CVSS base score of 7.8.
Cisco released software updates that address these vulnerabilities, according to an advisory. There are no workarounds that address these vulnerabilities.
These vulnerabilities affect the following Cisco products if they are running a vulnerable release of Cisco SD-WAN Software:
- SD-WAN vBond Orchestrator Software
- SD-WAN vEdge Cloud Routers
- SD-WAN vEdge Routers
- SD-WAN vManage Software
- SD-WAN vSmart Controller Software
The following are versions of Cisco SD-WAN Software Release that suffer from CVE-2022-20775 and their fixes:
- 18.4 and earlier migrate to a fixed release
- 19.2 migrate to a fixed release
- 20.3 migrate to a fixed release
- 20.6 migrate to 20.6.3
- 20.7 migrate to 20.7.2
- 20.8 migrate to 20.8.1
- 20.9, not affected
The following are versions of Cisco SD-WAN Software Release that suffer from CVE-2022-20818 and their fixes:
- 18.4 and earlier migrate to a fixed release
- 19.2 migrate to a fixed release
- 20.3 migrate to a fixed release
- 20.6 migrate to a fixed release
- 20.7 migrate to a fixed release
- 20.8 migrate to a fixed release
- 20.9, not affected
Click here for more information on multiple other security fixes from Cisco.

