OS Command Injection in ConfD - CVE-2022-20655
Published: January 24, 2022
Vulnerability details
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to insufficient validation of a process argument on an affected device. A local user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Carrier Packet Transport (CPT) System
Virtual Topology System
Ultra Gateway Platform
Cisco IOS XE SD-WAN
Cisco SD-WAN vSmart Software
Cisco SD-WAN vBond Orchestrator
Enterprise NFV Infrastructure Software
Cisco Network Services Orchestrator (NSO)
Cisco IOS XR
Catalyst SD-WAN Manager (formerly SD-WAN vManage)
Cisco SD-WAN vEdge Routers
How to mitigate CVE-2022-20655
Virtual Topology System - update to 2.6.5
Enterprise NFV Infrastructure Software - update to 3.12.1
Cisco Network Services Orchestrator (NSO) - addressed in versions 4.3.9.1, 4.4.5.6, 4.4.8, 4.5.7, 4.6.1.7, 4.6.2, 4.7.1, 5.1.0.1, 5.2
Ultra Gateway Platform - update to 6.15.0
Cisco IOS XR - addressed in versions 7.0.2, 7.1.1
Cisco IOS XE SD-WAN - addressed in versions 16.10.2, 16.12.1 b, 17.2.1r
Catalyst SD-WAN Manager (formerly SD-WAN vManage) - addressed in versions 18.4.4, 19.2.1, 19.3.0, 20.1.1
Cisco SD-WAN vSmart Software - addressed in versions 18.4.4, 19.2.1, 19.3.0, 20.1.1
Cisco SD-WAN vBond Orchestrator - addressed in versions 18.4.4, 19.2.1, 19.3.0, 20.1.1
Cisco SD-WAN vEdge Routers - addressed in versions 18.4.4, 19.2.1, 19.3.0, 20.1.1