CVE-2023-20191
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2023-20191 is a vulnerability affecting the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software. This issue, caused by incomplete support for this feature, allows unauthenticated, remote attackers to bypass configured ACLs. An attacker could potentially exploit this flaw by sending malicious traffic through an affected device, bypassing the ACL and gaining unauthorized access. Cisco has provided workarounds to address this vulnerability, which is part of the September 2023 release of the Cisco IOS XR Software Security Advisory Bundled Publication.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS
- Cisco IOS XR
Affected Vendors
- Cisco Systems Inc
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions