Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2022-20775
Cisco SD-WAN Software Privilege Escalation Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .1247 96.1 YES
AFFECTED
Product Versions Fixed
Cisco Catalyst SD-WAN 18.3.1 – —
Cisco Catalyst SD-WAN Manager 20.1.12 – —
Cisco SD-WAN vContainer 18.4.5 – —
Cisco SD-WAN vEdge Cloud 19.2.1 – —
Cisco SD-WAN vEdge Router 18.4.303 – —
TIMELINE
Nov 2 Reserved by cisco
Sep 30 Published (CNA: cisco)
Feb 25 Added to CISA KEV, remediation due 2026-02-27
Description
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges.
This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| November 2, 2021 | Reserved | Reserved by cisco |
| September 30, 2022 | Published | Published (CNA: cisco) |
| February 25, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-02-27 |
Affected
Affected products and packages — 5 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Cisco | Cisco Catalyst SD-WAN | — | 18.3.1 | — |
| Cisco | Cisco Catalyst SD-WAN Manager | — | 20.1.12 | — |
| Cisco | Cisco SD-WAN vContainer | — | 18.4.5 | — |
| Cisco | Cisco SD-WAN vEdge Cloud | — | 19.2.1 | — |
| Cisco | Cisco SD-WAN vEdge Router | — | 18.4.303 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-20775 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.