CVE-2022-20655

EUVD-2022-25905
A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack.
 The vulnerability is due to insufficient validation of a process argument on an affected device. An attacker could exploit this vulnerability by injecting commands during the execution of this process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privilege level of ConfD, which is commonly root.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ciscoios_xr_software
𝑥
< 7.0.2
ADP
ciscoios_xr_software
7.1.0 ≤
𝑥
< 7.1.1
ADP
ciscovirtual_topology_system
𝑥
< 2.6.5
ADP
cisconetwork_services_orchestrator
𝑥
< 4.3.9.1
ADP
cisconetwork_services_orchestrator
4.4.0.0 ≤
𝑥
< 4.4.5.6
ADP
cisconetwork_services_orchestrator
4.5.0 ≤
𝑥
< 4.5.7
ADP
cisconetwork_services_orchestrator
4.6.0 ≤
𝑥
< 4.6.1.7
ADP
cisconetwork_services_orchestrator
4.7.0 ≤
𝑥
< 4.7.1
ADP
cisconetwork_services_orchestrator
5.1.0 ≤
𝑥
< 5.1.0.1
ADP
ciscoenterprise_nfv_infrastructure_software
𝑥
< 3.12.1
ADP
ciscocatalyst_sd-wan_manager
𝑥
< 18.4.4
ADP
ciscocatalyst_sd-wan_manager
19.2.0 ≤
𝑥
< 19.2.1
ADP
ciscoios_xe_catalyst_sd-wan
𝑥
< 16.10.2
ADP
ciscoios_xe_catalyst_sd-wan
16.12.0 ≤
𝑥
< 16.12.1b
ADP
ciscoios_xe_catalyst_sd-wan
17.2.0 ≤
𝑥
< 17.2.1r
ADP
ciscosd-wan_vedge_router
𝑥
< 18.4.4
ADP
ciscosd-wan_vedge_router
19.2.0 ≤
𝑥
< 19.2.1
ADP
ciscocarrier_packet_transport
𝑥
< *
ADP