VDB
CVE-2023-20191
CVE-2023-20191
PUBLISHED
Es besteht eine Schwachstelle in Cisco IOS XR. Dieser Fehler besteht in der Zugriffskontrolllisten (ACL)-Verarbeitung auf MPLS-Schnittstellen in der Ingress-Richtung der XR-Software aufgrund einer unvollständigen Unterstützung für diese Funktion. Ein entfernter Angreifer kann diese Schwachstelle ausnutzen, um Sicherheitsmaßnahmen zu umgehen.
EPSS 0.02% · 6.5th percentile
Risk Scores
EPSS Score
0.02%
6.5th percentile
Exploit Intelligence
- cisco-sa-dnx-acl-PyzDkeYF (circl)
Timeline
- Sep 13, 2023 CVE Published
- Sep 14, 2023 EPSS Score
- Oct 16, 2023 EPSS Score
- Nov 18, 2023 EPSS Score
- Dec 20, 2023 EPSS Score
- Jan 22, 2024 EPSS Score
- Feb 23, 2024 EPSS Score
- Mar 26, 2024 EPSS Score
- Apr 28, 2024 EPSS Score
- May 30, 2024 EPSS Score
- Jul 1, 2024 EPSS Score
- Aug 2, 2024 CVE Updated
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2355.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2355 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lnt-L9zOkBz5 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-ipxe-sigbypass-pymfyqgB advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xr-cfm-3pWN8MKt advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnx-acl-PyzDkeYF advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-comp3acl-vGmp6BQ3 advisory