Access Control Bypass Vulnerability in Cisco IOS XR Software
CVE-2023-20191

7.5HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
13 September 2023

Summary

A vulnerability exists in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software. This flaw can be exploited by an unauthenticated remote attacker who is able to send traffic through the affected device, thereby bypassing configured ACLs. The root cause of this vulnerability is incomplete support for ACL features. Cisco has provided workarounds to mitigate the risk associated with this issue. For more details, refer to the official Cisco security advisory.

Affected Version(s)

Cisco IOS XR Software 6.4.1

Cisco IOS XR Software 6.5.1

Cisco IOS XR Software 6.5.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.