CVE-2022-20775 is a local privilege escalation vulnerability in Cisco SD-WAN Software CLI that allows authenticated, local attackers to execute commands as root. While the affected products are commonly internet-facing, the vulnerability itself requires existing local access and cannot be directly exploited over the internet.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2022-09-30
Added to CISA KEV: 2026-02-25 1244 DAYS BETWEEN CVE AND KEV
CVE-2022-20775 is a high-severity vulnerability in the command-line interface (CLI) of Cisco SD-WAN Software, characterized by improper access controls that allow for privilege escalation [2] [3].
The attacks were attributed by Cisco Talos to UAT-8616, a “highly sophisticated cyber threat actor” that has been active since at least 2023. ... CVE-2022-20775, disclosed in September 2022, is a high-severity path traversal issue that allows an authenticated attacker to execute arbitrary commands w…
CVE-2022-20775 Detail Description A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI.
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malici…
CVE-2022-20775 could enable an authenticated local attacker to escalate their privileges. The activity has been linked to ongoing malicious ... Get started. Cisco SD-WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775) in active exploitation. Author - Sophos Logo.CVE-2026-20127 can lead to a remote…
Malicious cyber actors are targeting and compromising Cisco SD-WAN systems deployed by organizations worldwide. These actors have exploited ...