Command Injection Vulnerability in ConfD Could Allow Authenticated Attacker to Execute Arbitrary Commands with Root Privileges
CVE-2022-20655
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 15 November 2024
What is CVE-2022-20655?
An issue within the command line interface (CLI) implementation in Cisco's ConfD can allow authenticated, local attackers to conduct command injection attacks. This vulnerability stems from insufficient validation of process arguments, enabling an attacker to inject malicious commands during execution. Successfully exploiting this vulnerability can lead to the execution of arbitrary commands on the underlying operating system with the same privileges as ConfD, often equivalent to root access, thereby posing severe risks to system security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Carrier Packet Transport 3.5
Cisco Carrier Packet Transport 3.1
Cisco Carrier Packet Transport 3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved