PT-2022-6016 · Cisco · Cisco Sd-Wan+5

Published

2022-09-29

·

Updated

2024-01-15

·

CVE-2022-20818

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco SD-WAN Software versions (affected versions not specified) Cisco SD-WAN vBond Orchestrator versions (affected versions not specified) Cisco SD-WAN vEdge Cloud Routers versions (affected versions not specified) Cisco SD-WAN vEdge Routers versions (affected versions not specified) Cisco SD-WAN vSmart Controller versions (affected versions not specified) Cisco SD-WAN vManage versions (affected versions not specified)
Description The issue is related to improper access controls on commands within the application CLI of Cisco SD-WAN Software, allowing an authenticated, local attacker to gain elevated privileges. An attacker could exploit this by running a malicious command on the application CLI, potentially executing arbitrary commands as the root user. The vulnerability is also associated with incorrect restriction of the directory path name with limited access, which could allow an attacker to create or overwrite critical files as the root user.
Recommendations For Cisco SD-WAN Software, consider restricting access to the CLI to minimize the risk of exploitation. For Cisco SD-WAN vBond Orchestrator, Cisco SD-WAN vEdge Cloud Routers, Cisco SD-WAN vEdge Routers, Cisco SD-WAN vSmart Controller, and Cisco SD-WAN vManage, restrict access to the vulnerable CLI commands until a patch is available. As a temporary workaround, consider disabling commands that allow execution of arbitrary commands as the root user until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2022-07467
CVE-2022-20818

Affected Products

Cisco Sd-Wan
Cisco Sd-Wan Vbond Orchestrator
Cisco Sd-Wan Vedge Cloud Routers
Cisco Sd-Wan Vedge Routers
Cisco Sd-Wan Vmanage
Cisco Sd-Wan Vsmart Controller