CVE-2023-20191

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 13, 2023
Updated: Jan 25, 2024
CWE ID 863
CWE ID 284

Summary

CVE-2023-20191 is a vulnerability affecting the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software. This issue, caused by incomplete support for this feature, allows unauthenticated, remote attackers to bypass configured ACLs. An attacker could potentially exploit this flaw by sending malicious traffic through an affected device, bypassing the ACL and gaining unauthorized access. Cisco has provided workarounds to address this vulnerability, which is part of the September 2023 release of the Cisco IOS XR Software Security Advisory Bundled Publication.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco IOS
  • Cisco IOS XR

Affected Vendors

  • Cisco Systems Inc