7.2
CVSSv3

CVE-2024-20263

Published: 26/01/2024 Updated: 06/02/2024
CVSS v3 Base Score: 7.2 | Impact Score: 2.7 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series Managed Switches could allow an unauthenticated, remote malicious user to bypass protection offered by a configured ACL on an affected device. This vulnerability is due to incorrect processing of ACLs on a stacked configuration when either the primary or backup switches experience a full stack reload or power cycle. An attacker could exploit this vulnerability by sending crafted traffic through an affected device. A successful exploit could allow the malicious user to bypass configured ACLs, causing traffic to be dropped or forwarded in an unexpected manner. The attacker does not have control over the conditions that result in the device being in the vulnerable state. Note: In the vulnerable state, the ACL would be correctly applied on the primary devices but could be incorrectly applied to the backup devices.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco cbs250-8t-d_firmware

cisco cbs250-8pp-d_firmware

cisco cbs250-8t-e-2g_firmware

cisco cbs250-8pp-e-2g_firmware

cisco cbs250-8p-e-2g_firmware

cisco cbs250-8fp-e-2g_firmware

cisco cbs250-16t-2g_firmware

cisco cbs250-16p-2g_firmware

cisco cbs250-24t-4g_firmware

cisco cbs250-24pp-4g_firmware

cisco cbs250-24p-4g_firmware

cisco cbs250-24fp-4g_firmware

cisco cbs250-48t-4g_firmware

cisco cbs250-48pp-4g_firmware

cisco cbs250-48p-4g_firmware

cisco cbs250-24t-4x_firmware

cisco cbs250-24p-4x_firmware

cisco cbs250-24fp-4x_firmware

cisco cbs250-48t-4x_firmware

cisco cbs250-48p-4x_firmware

cisco cbs350-8t-e-2g_firmware

cisco cbs350-8p-2g_firmware

cisco cbs350-8p-e-2g_firmware

cisco cbs350-8fp-2g_firmware

cisco cbs350-8fp-e-2g_firmware

cisco cbs350-8s-e-2g_firmware

cisco cbs350-16t-2g_firmware

cisco cbs350-16t-e-2g_firmware

cisco cbs350-16p-2g_firmware

cisco cbs350-16p-e-2g_firmware

cisco cbs350-16fp-2g_firmware

cisco cbs350-24t-4g_firmware

cisco cbs350-24p-4g_firmware

cisco cbs350-24fp-4g_firmware

cisco cbs350-24s-4g_firmware

cisco cbs350-48t-4g_firmware

cisco cbs350-48p-4g_firmware

cisco cbs350-48fp-4g_firmware

cisco cbs350-24t-4x_firmware

cisco cbs350-24p-4x_firmware

cisco cbs350-24fp-4x_firmware

cisco cbs350-48t-4x_firmware

cisco cbs350-48p-4x_firmware

cisco cbs350-48fp-4x_firmware

cisco cbs350-8mgp-2x_firmware

cisco cbs350-8mp-2x_firmware

cisco cbs350-24mgp-4x_firmware

cisco cbs350-12np-4x_firmware

cisco cbs350-24ngp-4x_firmware

cisco cbs350-48ngp-4x_firmware

cisco cbs350-8xt_firmware

cisco cbs350-12xs_firmware

cisco cbs350-12xt_firmware

cisco cbs350-16xts_firmware

cisco cbs350-24xs_firmware

cisco cbs350-24xt_firmware

cisco cbs350-24xts_firmware

cisco cbs350-48xt-4x_firmware

cisco sg350xg-2f10_firmware

cisco sg350xg-24f_firmware

cisco sg350xg-24t_firmware

cisco sg350xg-48t_firmware

cisco sg350x-24_firmware

cisco sg350x-24p_firmware

cisco sg350x-24mp_firmware

cisco sg350x-48_firmware

cisco sg350x-48p_firmware

cisco sg350x-48mp_firmware

cisco sg550xg-8f8t_firmware

cisco sg550xg-24f_firmware

cisco sg550xg-24t_firmware

cisco sg550x-48t_firmware

cisco sg550x-24_firmware

cisco sg550x-24p_firmware

cisco sg550x-24mp_firmware

cisco sg550x-24mpp_firmware

cisco sg550x-48_firmware

cisco sg550x-48p_firmware

cisco sg550x-48mp_firmware

cisco sf550x-24_firmware

cisco sf550x-24p_firmware

cisco sf550x-24mp_firmware

cisco sf550x-48_firmware

cisco sf550x-48p_firmware

cisco sf550x-48mp_firmware

Vendor Advisories

A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series Managed Switches could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device This vulnerability is due to incorrect proces ...