Access Control Bypass Vulnerability in Cisco IOS XR Software
CVE-2023-20191
7.5HIGH
Summary
A vulnerability exists in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software. This flaw can be exploited by an unauthenticated remote attacker who is able to send traffic through the affected device, thereby bypassing configured ACLs. The root cause of this vulnerability is incomplete support for ACL features. Cisco has provided workarounds to mitigate the risk associated with this issue. For more details, refer to the official Cisco security advisory.
Affected Version(s)
Cisco IOS XR Software 6.4.1
Cisco IOS XR Software 6.5.1
Cisco IOS XR Software 6.5.2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved