VDB

CISCO-SA-SD-WAN-PRIV-E6E8TEDF

CISCO-SA-SD-WAN-PRIV-E6E8TEDF PUBLISHED CVSS 7.800000190734863 HIGH

Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Cisco SD-WAN vContainer
Cisco SD-WAN vEdge Cloud
Cisco SD-WAN vEdge Router
Cisco Catalyst SD-WAN
Cisco Catalyst SD-WAN Manager

Timeline

  • Sep 28, 2022 CVE Published
  • Feb 25, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›