Cisco SD-WAN Software Privilege Escalation Vulnerabilities
CVE-2022-20818
7.8HIGH
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 30 September 2022
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2022-20818?
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Affected Version(s)
Cisco SD-WAN Solution
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.