boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2022-20775

Cisco SD-WAN Software Privilege Escalation Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .1247   96.1   YES
AFFECTED
  Product                        Versions    Fixed
  Cisco Catalyst SD-WAN          18.3.1 –    —
  Cisco Catalyst SD-WAN Manager  20.1.12 –   —
  Cisco SD-WAN vContainer        18.4.5 –    —
  Cisco SD-WAN vEdge Cloud       19.2.1 –    —
  Cisco SD-WAN vEdge Router      18.4.303 –  —
TIMELINE
  Nov 2   Reserved by cisco
  Sep 30  Published (CNA: cisco)
  Feb 25  Added to CISA KEV, remediation due 2026-02-27
CWE-25 · CNA: cisco · CVSS v3.1 · 4 references · KEV due February 27, 2026

Description

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
November 2, 2021ReservedReserved by cisco
September 30, 2022PublishedPublished (CNA: cisco)
February 25, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-02-27

Affected

Affected products and packages — 5 rows
VendorProduct / PackageEcosystemVersion introducedFixed
CiscoCisco Catalyst SD-WAN—18.3.1—
CiscoCisco Catalyst SD-WAN Manager—20.1.12—
CiscoCisco SD-WAN vContainer—18.4.5—
CiscoCisco SD-WAN vEdge Cloud—19.2.1—
CiscoCisco SD-WAN vEdge Router—18.4.303—

Weaknesses

CWE-25

References (4)

Related

Authoritative record: CVE-2022-20775 at cve.org

Vendors: cisco

Weaknesses: CWE-25

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-20775 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.