CVE-2024-20465
CVSS 3.1 Score 5.8 of 10 (medium)
Details
Summary
CVE-2024-20465 is a newly disclosed vulnerability affecting Cisco IOS Software on Industrial Ethernet 4000, 4010, and 5000 Series Switches. This issue stems from the improper handling of IPv4 Access Control Lists (ACLs) on switched virtual interfaces when an administrator enables or disables Resilient Ethernet Protocol (REP). Unauthenticated, remote attackers can exploit this flaw to bypass valid ACLs on the compromised devices, potentially gaining unauthorized access. The vulnerability could lead to significant security risks, making it crucial for organizations using these Cisco switch models to apply the necessary patches as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS
Affected Vendors
- Cisco