QID 317419
Date Published: 2024-03-26
QID 317419: Cisco Nexus 3000 and 9000 Series Switches Port Channel Access Control List (ACL) Programming Vulnerability (cisco-sa-nxos-po-acl-TkyePgvL)
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated remote attacker to send traffic that should be blocked through an affected device.
Affected Products
Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode if they were running Cisco NX-OS Software Release 9.3(10), 9.3(11), or 9.3(12) and had an ingress ACL configured on at least one port channel sub interface.
QID Detection Logic(Authenticated):
It checks for vulnerable version of Cisco NX-OS using show version Command.
Note: This QID doesn't check for the ACL configuration, hence marked potential
A successful exploit could allow the attacker to access network resources that should be protected by an ACL that was applied on port channel subinterfaces.
Customers are advised to refer to cisco-sa-nxos-po-acl-TkyePgvL for more information.
- cisco-sa-nxos-po-acl-TkyePgvL -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-po-acl-TkyePgvL
CVEs related to QID 317419
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-nxos-po-acl-TkyePgvL |
|