Cisco Small Business Series Switches Stacked Reload ACL Bypass (cisco-sa-sb-bus-acl-bypass-5zn9hNJk)

high Nessus Plugin ID 189633

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series Managed Switches could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device.

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwf48882, CSCwh68993

See Also

http://www.nessus.org/u?08defa12

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwf48882

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh68993

Plugin Details

Severity: High

ID: 189633

File Name: cisco-sa-sb-bus-acl-bypass-5zn9hNJk.nasl

Version: 1.1

Type: remote

Family: CISCO

Published: 1/26/2024

Updated: 2/7/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.8

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2024-20263

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: x-cpe:/o:cisco:small_business_series_switch, x-cpe:/h:cisco:small_business_series_switch

Required KB Items: Cisco/Small_Business_Router/Version, Cisco/Small_Business_Router/Model

Exploit Ease: No known exploits are available

Patch Publication Date: 1/24/2024

Vulnerability Publication Date: 1/24/2024

Reference Information

CVE: CVE-2024-20263

CISCO-SA: cisco-sa-sb-bus-acl-bypass-5zn9hNJk

IAVA: 2024-A-0055

CISCO-BUG-ID: CSCwf48882, CSCwh68993