VDB
CVE-2022-20655
CVE-2022-20655
PUBLISHED
CVSS 8.800000190734863 HIGH
A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient validation of a process argument on an affected device. An attacker could exploit this vulnerability by injecting commands during the execution of this process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privilege level of ConfD, which is commonly root.
EPSS 0.40% · 61.1th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.40%
61.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Catalyst SD-WAN | N/A |
| Cisco | Cisco IOS XE Catalyst SD-WAN | N/A |
| cisco | catalyst_sd-wan_manager | 19.2.0, 0 |
| cisco | ios_xr_software | 0, 7.1.0 |
| cisco | virtual_topology_system | 0 |
| Cisco | Cisco Catalyst SD-WAN Manager | N/A |
| cisco | carrier_packet_transport | 0 |
| Cisco | Cisco Network Services Orchestrator | N/A |
| Cisco | Cisco SD-WAN vEdge Router | N/A |
| Cisco | Cisco Enterprise NFV Infrastructure Software | N/A |
| cisco | ios_xe_catalyst_sd-wan | 17.2.0, 0, 16.12.0 |
| Cisco | Cisco Ultra Gateway Platform | N/A |
| cisco | network_services_orchestrator | 4.6.0, 5.1.0, 4.5.0 |
| cisco | enterprise_nfv_infrastructure_software | 0 |
| Cisco | Cisco Carrier Packet Transport | 1.0.2, 1.1.1, 1.1.2 |
| Cisco | Cisco IOS XR Software | * |
| Cisco | Cisco Virtual Topology System (VTS) | N/A |
| cisco | sd-wan_vedge_router | 0, 19.2.0 |
Exploit Intelligence
- cisco-sa-cli-cmdinj-4MttWZPB (circl)
- cisco-sa-confdcli-cmdinj-wybQDSSh (circl)
Timeline
- Jan 20, 2022 CVE Published
- Jan 21, 2022 CVE Updated
- Nov 16, 2024 EPSS Score
- Dec 5, 2024 EPSS Score
- Dec 22, 2024 EPSS Score
- Jan 9, 2025 EPSS Score
- Jan 26, 2025 EPSS Score
- Feb 13, 2025 EPSS Score
- Mar 3, 2025 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 20, 2025 EPSS Score
- Apr 7, 2025 EPSS Score
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cli-cmdinj-4MttWZPB advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-dos-9D3hJLuj advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-confdcli-cmdinj-wybQDSSh advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rcm-vuls-7cS3Nuq advisory
- cisco-sa-cli-cmdinj-4MttWZPB url
- cisco-sa-confdcli-cmdinj-wybQDSSh url
- https://nvd.nist.gov/vuln/detail/CVE-2022-20655 advisory