← Vulnerability feed

Vulnerability record · CVE-2022-20818 · published 30 September 2022

CVE-2022-20818: Cisco sd-wan vbond orchestrator path traversal vulnerability

Cisco · Sd Wan Vbond Orchestrator

Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

7.8 CVSS 3.1 High EPSS 0.63% · top 51.8% CWE-25 · CWE-25CWE-22 · Path traversal
7.8CVSS 3.1 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-20818 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-20182Cisco Catalyst SD-WAN peering authentication bypass grants admin accessThe peering authentication mechanism in Cisco Catalyst SD-WAN Controller, Manager and Validator does not work properly, allowing crafted requests to …KEVEPSS 92%analysed10.0CVE-2026-20127Cisco Catalyst SD-WAN peering authentication bypassThe peering authentication mechanism in Cisco Catalyst SD-WAN Controller, Manager and Validator does not work properly, letting an unauthenticated re…KEVEPSS 88%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed7.8CVE-2026-20245Cisco Catalyst SD-WAN CLI command injection via crafted file uploadCisco Catalyst SD-WAN Controller, Manager and Validator fail to properly validate user-supplied input in the CLI, allowing an authenticated local att…KEVEPSS 25%analysed7.8CVE-2022-20775Cisco SD-WAN CLI access control flaw allows root privilege escalationCisco SD-WAN Software has improper access controls on commands within the application CLI, letting an authenticated local attacker run a crafted comm…KEVEPSS 12%analysed9.9CVE-2020-3374Cisco sd-wan improper authorization vulnerabilityA vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author…EPSS 1.9%9.8CVE-2021-1468Cisco catalyst sd-wan manager improper input validation vulnerabilityMultiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…EPSS 2.0%9.8CVE-2021-1479Cisco catalyst sd-wan manager memory buffer overflow vulnerabilityMultiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authe…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2022-20818), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.