SB2023110326 - Access Control Policy Bypass in multiple Cisco Products
Published: November 3, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Business Logic Errors (CVE-ID: CVE-2023-20246)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a logic error when the access control policies are being populated. A remote attacker can establish a connection to an affected device and bypass configured access control rules on the affected system.
Remediation
Install update from vendor's website.