Security News

Cybersecurity news aggregator

🌐
CRITICAL News Cisco Security

Cisco SD-WAN Software Privilege Escalation Vulnerabilities

Multiple privilege escalation vulnerabilities (CVE-2022-20775 and CVE-2022-20818, CVSS 7.8 HIGH) in Cisco SD-WAN Software allow an authenticated local attacker to execute arbitrary commands as root via malicious CLI commands due to improper access controls. Affected versions include Cisco Catalyst SD-WAN Manager before 20.6.3 and 20.7.x before 20.7.2, and Cisco SD-WAN vBond Orchestrator, vManage, vSmart Controller, and SD-WAN software before version 20.9. Cisco has released fixed versions 20.6.3, 20.7.2, and 20.9, and there are no available workarounds.
Read Full Article →

Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF <br/>Security Impact Rating: High <br/>CVE: CVE-2022-20775,CVE-2022-20818

Share this article