Cisco fixed multiple high-rated vulnerabilities in the CLI of Cisco SD-WAN Software that could allow an authenticated, local attacker to gain elevated privileges.

These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

The two vulnerabilities are CVE-2022-20775 and CVE-2022-20818, which have a CVSS base score of 7.8.

Cisco released software updates that address these vulnerabilities, according to an advisory. There are no workarounds that address these vulnerabilities.

These vulnerabilities affect the following Cisco products if they are running a vulnerable release of Cisco SD-WAN Software:

Schneider Bold
  • SD-WAN vBond Orchestrator Software
  • SD-WAN vEdge Cloud Routers
  • SD-WAN vEdge Routers
  • SD-WAN vManage Software
  • SD-WAN vSmart Controller Software

The following are versions of Cisco SD-WAN Software Release that suffer from CVE-2022-20775 and their fixes:

  • 18.4 and earlier migrate to a fixed release
  • 19.2 migrate to a fixed release
  • 20.3 migrate to a fixed release
  • 20.6 migrate to 20.6.3
  • 20.7 migrate to 20.7.2
  • 20.8 migrate to 20.8.1
  • 20.9, not affected

The following are versions of Cisco SD-WAN Software Release that suffer from CVE-2022-20818 and their fixes:

  • 18.4 and earlier migrate to a fixed release
  • 19.2 migrate to a fixed release
  • 20.3 migrate to a fixed release
  • 20.6 migrate to a fixed release
  • 20.7 migrate to a fixed release
  • 20.8 migrate to a fixed release
  • 20.9, not affected

Click here for more information on multiple other security fixes from Cisco.

ISSSource

Pin It on Pinterest

Share This