Access Control Bypass in Cisco Catalyst 9500X and 9600X Series Switches
CVE-2025-20316
5.3MEDIUM
What is CVE-2025-20316?
A vulnerability exists in the access control list (ACL) programming of Cisco IOS XE Software that affects Catalyst 9500X and 9600X Series Switches. This vulnerability allows a remote, unauthenticated attacker to bypass configured ACLs by flooding traffic from an unlearned MAC address on a switch virtual interface (SVI) experiencing an egress ACL. Potential exploitation occurs when the VLAN's MAC address table is flushed or becomes full, enabling an attacker to circumvent security controls.
Affected Version(s)
Cisco IOS XE Software 17.7.1
Cisco IOS XE Software 17.10.1
Cisco IOS XE Software 17.10.1b