CVE-2024-20465

CVSS 3.1 Score 5.8 of 10 (medium)

Details

Published Sep 25, 2024
Updated: Oct 24, 2024
CWE ID 284

Summary

CVE-2024-20465 is a newly disclosed vulnerability affecting Cisco IOS Software on Industrial Ethernet 4000, 4010, and 5000 Series Switches. This issue stems from the improper handling of IPv4 Access Control Lists (ACLs) on switched virtual interfaces when an administrator enables or disables Resilient Ethernet Protocol (REP). Unauthenticated, remote attackers can exploit this flaw to bypass valid ACLs on the compromised devices, potentially gaining unauthorized access. The vulnerability could lead to significant security risks, making it crucial for organizations using these Cisco switch models to apply the necessary patches as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share