CVE-2024-20291
MEDIUMDescription
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked through an affected device. This vulnerability is due to incorrect hardware programming that occurs when configuration changes are made to port channel member ports. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to access network resources that should be protected by an ACL that was applied on port channel subinterfaces.
Is your site exposed to CVE-2024-20291?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | nx-os |
| cisco | nx-os |
| cisco | nx-os |
| cisco | nexus_3000_in_standalone_nx-os_mode |
| cisco | nexus_3048 |
| cisco | nexus_31108pc-v |
| cisco | nexus_31108tc-v |
| cisco | nexus_31128pq |
| cisco | nexus_3132c-z |
| cisco | nexus_3132q-v |
| cisco | nexus_3132q-xl |
| cisco | nexus_3164q |
| cisco | nexus_3172pq |
| cisco | nexus_3172pq-xl |
| cisco | nexus_3172tq |
| cisco | nexus_3172tq-32t |
| cisco | nexus_3172tq-xl |
| cisco | nexus_3232c |
| cisco | nexus_3264c-e |
| cisco | nexus_3264q |
| cisco | nexus_3408-s |
| cisco | nexus_34180yc |
| cisco | nexus_34200yc-sm |
| cisco | nexus_3432d-s |
| cisco | nexus_3464c |
| cisco | nexus_3524-x |
| cisco | nexus_3524-xl |
| cisco | nexus_3548-x |
| cisco | nexus_3548-xl |
| cisco | nexus_36180yc-r |
| cisco | nexus_9000_in_standalone_nx-os_mode |
| cisco | nexus_9000v |
| cisco | nexus_92160yc-x |
| cisco | nexus_92300yc |
| cisco | nexus_92304qc |
| cisco | nexus_92348gc-fx3 |
| cisco | nexus_92348gc-x |
| cisco | nexus_9236c |
| cisco | nexus_9272q |
| cisco | nexus_93108tc-ex |
| cisco | nexus_93108tc-ex-24 |
| cisco | nexus_93108tc-fx |
| cisco | nexus_93108tc-fx-24 |
| cisco | nexus_93108tc-fx3 |
| cisco | nexus_93108tc-fx3h |
| cisco | nexus_93108tc-fx3p |
| cisco | nexus_93120tx |
| cisco | nexus_9316d-gx |
| cisco | nexus_93180lc-ex |
| cisco | nexus_93180yc-ex |
| cisco | nexus_93180yc-ex-24 |
| cisco | nexus_93180yc-fx |
| cisco | nexus_93180yc-fx-24 |
| cisco | nexus_93180yc-fx3 |
| cisco | nexus_93180yc-fx3h |
| cisco | nexus_93180yc-fx3s |
| cisco | nexus_93216tc-fx2 |
| cisco | nexus_93240yc-fx2 |
| cisco | nexus_9332c |
| cisco | nexus_9332d-gx2b |
| cisco | nexus_9332d-h2r |
| cisco | nexus_9332pq |
| cisco | nexus_93360yc-fx2 |
| cisco | nexus_9336c-fx2 |
| cisco | nexus_9336c-fx2-e |
| cisco | nexus_9336pq_aci_spine |
| cisco | nexus_93400ld-h1 |
| cisco | nexus_9348d-gx2a |
| cisco | nexus_9348gc-fx3 |
| cisco | nexus_9348gc-fxp |
| cisco | nexus_93600cd-gx |
| cisco | nexus_9364c |
| cisco | nexus_9364c-gx |
| cisco | nexus_9364c-h1 |
| cisco | nexus_9364d-gx2a |
| cisco | nexus_9364e-sg2 |
| cisco | nexus_9372px-e |
| cisco | nexus_9372tx-e |
| cisco | nexus_9396tx |
| cisco | nexus_9408 |
| cisco | nexus_9508 |
| cisco | nexus_9804 |
| cisco | nexus_9808 |
References
Frequently Asked Questions
What is CVE-2024-20291? +
How severe is CVE-2024-20291? +
What products are affected by CVE-2024-20291? +
How do I check if I'm vulnerable to CVE-2024-20291? +
Related Vulnerabilities
mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read_only mode …
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in …
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in …
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administrator verification takes …
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms …
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately …