PT-2023-9645 · Cisco · Cisco Industrial Ethernet 4000+3

Published

2023-11-08

·

Updated

2024-10-24

·

CVE-2024-20465

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches (affected versions not specified)
Description The issue is related to the incorrect handling of IPv4 access control lists (ACLs) on switched virtual interfaces when an administrator enables and disables Resilient Ethernet Protocol (REP). This could allow an unauthenticated, remote attacker to bypass a configured ACL by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.
Recommendations For Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches, update to the latest software version that addresses this vulnerability, as released by Cisco. As a temporary workaround, consider restricting access to the Resilient Ethernet Protocol (REP) feature until a patch is available. Avoid using the IPv4 ACLs on switched virtual interfaces when REP is enabled or disabled, until the issue is resolved. Note: There are no workarounds that address this vulnerability, so updating the software is the recommended course of action.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-09170
CVE-2024-20465

Affected Products

Cisco Industrial Ethernet 4000
Cisco Industrial Ethernet 4010
Cisco Industrial Ethernet 5000
Cisco Ios