PT-2022-6953 · Cisco · Cisco Ios Xr

Published

2022-10-27

·

Updated

2024-01-25

·

CVE-2023-20191

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS XR Software (affected versions not specified)
Description A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incomplete support for this feature. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider implementing workarounds that address this vulnerability. Restrict access to the affected MPLS interfaces to minimize the risk of exploitation. Avoid using the affected ACL processing feature until the issue is resolved.

Improper Access Control

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2023-05806
CVE-2023-20191

Affected Products

Cisco Ios Xr