{"id":"CVE-2022-20775","vendor_project":"Cisco","product":"SD-WAN","vulnerability_name":"Cisco SD-WAN Path Traversal Vulnerability","date_added":"2026-02-25","due_date":"2026-02-27","known_ransomware_use":"Unknown","short_description":"Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.","required_action":"Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.","cwes":"CWE-25;CWE-282","cvss_version":"3.1","cvss_severity":"HIGH","cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","nvd_published":"2022-09-30","nvd_status":"Analyzed","epss":0.12475,"epss_percentile":0.96036,"cvss_score":7.8,"days_published_to_kev":1244,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2022-20775","by":"CyberMax"}