Access Control Bypass in Cisco Catalyst 9500X and 9600X Series Switches
CVE-2025-20316
What is CVE-2025-20316?
A vulnerability exists in the access control list (ACL) programming of Cisco IOS XE Software that affects Catalyst 9500X and 9600X Series Switches. This vulnerability allows a remote, unauthenticated attacker to bypass configured ACLs by flooding traffic from an unlearned MAC address on a switch virtual interface (SVI) experiencing an egress ACL. Potential exploitation occurs when the VLAN's MAC address table is flushed or becomes full, enabling an attacker to circumvent security controls.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco IOS XE Software 17.7.1
Cisco IOS XE Software 17.10.1
Cisco IOS XE Software 17.10.1b
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved