Record summary

CVE-2022-20775 has a selected CVSS score of 7.8 (high). CISA lists CVE-2022-20775 in KEV.

Description

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Feb 25, 2026 · CISA
VulnCheck KEV
Listed · Feb 25, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2026 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus

Default status: unknown

CVE List18.3.1affected
19.2.1affected
17.2.4affected
19.3.0affected
18.3.0affected
18.3.4affected
18.4.303affected
18.4.0.1affected
17.2.9affected
18.3.7affected
18.2.0affected
17.2.10affected
Showing 12 of 112 version ranges

Default status: unknown

CVE List20.1.12affected
19.2.1affected
18.4.4affected
18.4.5affected
20.1.1.1affected
20.1.1affected
19.3.0affected
19.2.2affected
19.2.099affected
18.3.6affected
18.3.7affected
19.2.0affected
Showing 12 of 152 version ranges

Default status: unknown

CVE List18.4.5affected
20.1.12affected
18.3.6affected
19.2.1affected
19.3.0affected
20.1.1affected
19.2.2affected
18.3.8affected
18.4.3affected
18.4.4affected
18.4.302affected
19.1.0affected
Showing 12 of 36 version ranges

Default status: unknown

CVE List19.2.1affected
20.1.12affected
18.4.4affected
19.3.0affected
18.3.8affected
19.2.2affected
20.1.1affected
18.3.6affected
18.4.3affected
18.4.302affected
18.4.5affected
18.4.303affected
Showing 12 of 79 version ranges

Default status: unknown

CVE List18.4.303affected
18.3.7affected
19.3.0affected
18.2.0affected
20.1.12affected
19.2.099affected
17.2.10affected
18.3.3affected
18.3.6affected
19.0.0affected
17.2.6affected
18.4.0affected
Showing 12 of 82 version ranges
CISAVersion data not supplied

References

5