Cisco SD-WAN是美国思科(Cisco)公司的一种高度安全的云规模架构,具有开放性、可编程性和可扩展性。 Cisco SD-WAN Software存在路径遍历漏洞,该漏洞源于对应用程序CLI中的命令的访问控制不当,可能允许经过身份验证的本地攻击者获得提升的权限,成功利用此漏洞可以让攻击者执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco SD-WAN Solution | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2022-20818: Local Privilege Escalation via Partial File Read in Cisco SD-WAN | https://github.com/mbadanoiu/CVE-2022-20818 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-20919 | 8.6 HIGH | Cisco IOS and IOS XE Software Common Industrial Protocol Request Denial of Service Vulnera |
| CVE-2022-20856 | 8.6 HIGH | Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Mobility Den |
| CVE-2022-20848 | 8.6 HIGH | Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst 9100 Series Access Poi |
| CVE-2022-20847 | 8.6 HIGH | Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family DHCP Processing Den |
| CVE-2022-20855 | 7.9 HIGH | Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst Access Points Privileg |
| CVE-2022-20775 | 7.8 HIGH | Cisco SD-WAN Software Privilege Escalation Vulnerability |
| CVE-2022-20945 | 7.4 HIGH | Cisco Catalyst 9100 Series Access Points Association Request Denial of Service Vulnerabili |
| CVE-2022-20769 | 7.4 HIGH | Cisco Wireless LAN Controller AireOS Software FIPS Mode Denial of Service Vulnerability |
| CVE-2022-20930 | 6.7 MEDIUM | Cisco SD-WAN Software Arbitrary File Corruption Vulnerability |
| CVE-2022-20810 | 6.5 MEDIUM | Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Information Di |
| CVE-2022-20662 | 6.1 MEDIUM | Cisco Duo for macOS Authentication Bypass Vulnerability |
| CVE-2022-20851 | 5.5 MEDIUM | Cisco IOS XE Software Web UI Command Injection Vulnerability |
| CVE-2022-20850 | 5.5 MEDIUM | Cisco SD-WAN Arbitrary File Deletion Vulnerability |
| CVE-2022-20844 | 5.3 MEDIUM | Cisco Software-Defined Application Visibility and Control on Cisco vManage Static Username |
| CVE-2022-20728 | 4.7 MEDIUM | Cisco Access Points VLAN Bypass from Native VLAN Vulnerability |
No comments yet