#VU62344 Improper Privilege Management in Cisco SD-WAN vManage - CVE-2022-20739
Published: April 15, 2022
Cisco SD-WAN vManage
Cisco Systems, Inc
Description
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a file leveraged by a root user is executed when a low-privileged user runs specific commands. A local user can inject arbitrary commands to a specific file, then wait until an admin user executes specific commands and gain elevated privileges on the target system.