ZeroHour

CVE-2022-20775

KEV PoC large

Path Traversal Privilege Escalation in Cisco SD-WAN Software CLI

CISA: Cisco SD-WAN Path Traversal Vulnerability

CVSS 3.1
7.8 high
EPSS
12%p96
Published
()
KEV added
AI analysis

CVE-2022-20775 is a path traversal and improper access control flaw (CWE-22/CWE-25) in the CLI of Cisco SD-WAN Software that allows an authenticated, local attacker to gain elevated privileges. An attacker triggers it by running a maliciously crafted command in the application CLI, abusing weak access controls on CLI commands. A successful exploit yields arbitrary command execution as the root user, giving full control of the affected SD-WAN component. Organizations running Cisco SD-WAN / Catalyst SD-WAN components — SD-WAN Manager, vBond Orchestrator, vSmart Controller, and vEdge Cloud routers — are affected. The flaw is now being actively exploited: it was added to the CISA KEV catalog on 2026-02-25, prompting CISA Emergency Directive 26-03 and joint Five Eyes 'Hunt & Hardening' guidance, a public proof-of-concept exists, and EPSS estimates a 12.5% chance of exploitation within 30 days (96th percentile).

What to do: Upgrade affected SD-WAN components — Catalyst SD-WAN Manager, vBond Orchestrator, vSmart Controller, and vEdge Cloud — to the fixed releases listed in Cisco advisory cisco-sa-sd-wan-priv-E6e8tEdF, as there are no workarounds. Restrict CLI access to trusted administrators, review local accounts for unexpected additions or changes, and hunt for signs of compromise per CISA Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices. If patched software or cloud-service mitigations are unavailable, follow BOD 22-01 guidance and consider discontinuing use of the affected components.

Affected
Cisco SD-WAN Software (Catalyst SD-WAN)
Cisco Catalyst SD-WAN Manager (vManage)
Cisco SD-WAN vBond Orchestrator
Cisco SD-WAN vSmart Controller
Cisco SD-WAN vEdge Cloud Router
Estimated exposure
largeon the order of tens of thousands of SD-WAN controller and edge deployments (10k–100k systems) — an estimate — Cisco SD-WAN (Viptela) is a market-leading SD-WAN platform deployed across enterprise branch networks and managed service providers, with controller components (Manager/vBond/vSmart) deployed per overlay and vEdge Cloud at branch sites,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF

CISA Known Exploited Vulnerability
Affected
Cisco SD-WAN
Required action
Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
catalyst sd-wan manager, sd-wan vbond orchestrator, sd-wan vedge cloud, sd-wan vsmart controller, sd-wan
Weakness
CWE-25, CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news