Access Control Bypass Vulnerability in Cisco IOS XR Software
CVE-2023-20191
7.5HIGH
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 13 September 2023
What is CVE-2023-20191?
A vulnerability exists in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software. This flaw can be exploited by an unauthenticated remote attacker who is able to send traffic through the affected device, thereby bypassing configured ACLs. The root cause of this vulnerability is incomplete support for ACL features. Cisco has provided workarounds to mitigate the risk associated with this issue. For more details, refer to the official Cisco security advisory.
Affected Version(s)
Cisco IOS XR Software 6.4.1
Cisco IOS XR Software 6.5.1
Cisco IOS XR Software 6.5.2