CVE-2024-20291
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked through an affected device.
This vulnerability is due to incorrect hardware programming that occurs when configuration changes are made to port channel member ports. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to access network resources that should be protected by an ACL that was applied on port channel subinterfaces.
Una vulnerabilidad en la programación de la lista de control de acceso (ACL) para las subinterfaces del canal de puerto de los conmutadores Cisco Nexus de las series 3000 y 9000 en modo NX-OS independiente podría permitir que un atacante remoto no autenticado envíe tráfico que debería bloquearse a través de un dispositivo afectado. Esta vulnerabilidad se debe a una programación de hardware incorrecta que ocurre cuando se realizan cambios de configuración en los puertos miembros del canal de puertos. Un atacante podría aprovechar esta vulnerabilidad intentando enviar tráfico a través de un dispositivo afectado. Un exploit exitoso podría permitir al atacante acceder a recursos de red que deberían estar protegidos por una ACL que se aplicó en las subinterfaces del canal de puerto.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-11-08 CVE Reserved
- 2024-02-28 CVE Published
- 2024-02-29 EPSS Updated
- 2024-03-09 First Exploit
- 2024-08-09 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-284: Improper Access Control
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-po-acl-TkyePgvL |
URL | Date | SRC |
---|---|---|
https://github.com/Instructor-Team8/CVE-2024-20291-POC | 2024-03-09 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Cisco NX-OS Software Search vendor "Cisco" for product "Cisco NX-OS Software" | 9.3 Search vendor "Cisco" for product "Cisco NX-OS Software" and version "9.3" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco NX-OS Software Search vendor "Cisco" for product "Cisco NX-OS Software" | 9.3 Search vendor "Cisco" for product "Cisco NX-OS Software" and version "9.3" | en |
Affected
| ||||||
Cisco Search vendor "Cisco" | Cisco NX-OS Software Search vendor "Cisco" for product "Cisco NX-OS Software" | 9.3 Search vendor "Cisco" for product "Cisco NX-OS Software" and version "9.3" | en |
Affected
|