VYPR
Unrated severityNVD Advisory· Published Sep 30, 2022· Updated Nov 1, 2024

Cisco SD-WAN Arbitrary File Deletion Vulnerability

CVE-2022-20850

Description

A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting arbitrary file path information when using commands in the CLI of an affected device. A successful exploit could allow the attacker to delete arbitrary files from the file system of the affected device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated local attacker can delete arbitrary files via improper input validation in Cisco SD-WAN CLI.

Vulnerability

The vulnerability resides in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software. Due to insufficient input validation, an authenticated local attacker can inject arbitrary file path information when using CLI commands, allowing deletion of arbitrary files from the file system. Affected versions include Cisco Standalone IOS XE SD-WAN releases 16.9 (no fixed release, migrate), 16.10 (fixed in 16.10.1), while 16.11 and 16.12 are not affected. For Cisco SD-WAN Software, releases 18.3 and earlier (migrate), 18.4 (fixed in 18.4.5), and 19.2, 20.3, 20.6, 20.9 are not affected [1].

Exploitation

An attacker must have authenticated local access to the affected device's CLI. The attacker then injects arbitrary file path information into specific CLI commands to target files for deletion. No additional user interaction or privileges beyond authentication are required [1].

Impact

Successful exploitation allows the attacker to delete arbitrary files from the file system of the affected device, potentially causing denial of service or rendering the device inoperable [1].

Mitigation

Fixed releases are available: Cisco IOS XE SD-WAN version 16.10.1 and Cisco SD-WAN Software version 18.4.5. For releases without a fix (e.g., 16.9 and earlier, 18.3 and earlier), customers should migrate to a fixed release. No workarounds are documented. Customers should consult the Cisco Security Advisory for the most current information [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.