CVE Feed

    Dashboard / CVE / CVE-2022-20655

    CVE-2022-20655

    A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient validation of a process argument on an affected device. An attacker could exploit this vulnerability by injecting commands during the execution of this process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privilege level of ConfD, which is commonly root.

    Published:Nov 15, 2024
    Last Modified:Apr 15, 2026
    EPS:Nov 15, 2024
    EPSS Score:0.004
    CVSS Score:8.8

    Affected Products

    Vendor
    Cisco
    Product
    Carrier Packet Transport
    Vendor
    Cisco
    Product
    Catalyst Sd-wan Manager
    Vendor
    Cisco
    Product
    Enterprise Nfv Infrastructure Software
    Vendor
    Cisco
    Product
    Ios Xe Catalyst Sd-wan
    Vendor
    Cisco
    Product
    Ios Xr Software
    Vendor
    Cisco
    Product
    Network Services Orchestrator
    Vendor
    Cisco
    Product
    Sd-wan Vedge Router
    Vendor
    Cisco
    Product
    Virtual Topology System

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High