CVE-2024-20263 (CNNVD-202401-2249)

MEDIUM
中文标题:
Cisco Small Business 安全漏洞
英文标题:
A vulnerability with the access control list (ACL) management within a stacked switch configuration ...
CVSS分数: 5.8
发布时间: 2024-01-26 17:27:08
漏洞类型: 其他
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v3
漏洞描述
中文描述:

Cisco Small Business是美国思科(Cisco)公司的一个交换机。 Cisco Small Business 存在安全漏洞,该漏洞源于当主交换机或备用交换机经历完整堆栈重新加载或电源周期时,堆栈配置上的 ACL 处理不正确。

英文描述:

A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series Managed Switches could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device. This vulnerability is due to incorrect processing of ACLs on a stacked configuration when either the primary or backup switches experience a full stack reload or power cycle. An attacker could exploit this vulnerability by sending crafted traffic through an affected device. A successful exploit could allow the attacker to bypass configured ACLs, causing traffic to be dropped or forwarded in an unexpected manner. The attacker does not have control over the conditions that result in the device being in the vulnerable state. Note: In the vulnerable state, the ACL would be correctly applied on the primary devices but could be incorrectly applied to the backup devices.

CWE类型:
CWE-284
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
Cisco Cisco Small Business Smart and Managed Switches 2.0.0.73 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.0.0.73:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.1.0.63 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.1.0.63:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.2.0.63 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.2.0.63:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.2.0.66 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.2.0.66:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.2.5.68 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.2.5.68:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.2.7.07 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.2.7.07:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.2.8.04 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.2.8.04:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.3.0.130 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.3.0.130:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.3.5.63 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.3.5.63:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.4.0.91 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.4.0.91:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.4.0.94 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.4.0.94:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.4.5.71 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.4.5.71:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.0.78 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.0.78:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.0.79 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.0.79:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.0.82 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.0.82:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.0.83 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.0.83:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.0.89 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.0.89:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.0.90 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.0.90:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.0.92 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.0.92:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.5.47 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.5.47:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.7.85 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.7.85:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.8.12 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.8.12:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.8.15 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.8.15:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.9.13 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.9.13:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.9.15 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.9.15:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 2.5.9.16 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:2.5.9.16:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 3.0.0.61 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:3.0.0.61:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 3.0.0.69 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:3.0.0.69:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 3.1.0.57 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:3.1.0.57:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 3.1.1.7 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:3.1.1.7:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 3.2.0.84 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:3.2.0.84:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 3.2.0.89 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:3.2.0.89:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 3.2.1.1 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:3.2.1.1:*:*:*:*:*:*:*
Cisco Cisco Small Business Smart and Managed Switches 3.3.0.16 - - cpe:2.3:a:cisco:cisco_small_business_smart_and_managed_switches:3.3.0.16:*:*:*:*:*:*:*
cisco cbs250-8t-d_firmware * - - cpe:2.3:o:cisco:cbs250-8t-d_firmware:*:*:*:*:*:*:*:*
cisco cbs250-8pp-d_firmware * - - cpe:2.3:o:cisco:cbs250-8pp-d_firmware:*:*:*:*:*:*:*:*
cisco cbs250-8t-e-2g_firmware * - - cpe:2.3:o:cisco:cbs250-8t-e-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-8pp-e-2g_firmware * - - cpe:2.3:o:cisco:cbs250-8pp-e-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-8p-e-2g_firmware * - - cpe:2.3:o:cisco:cbs250-8p-e-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-8fp-e-2g_firmware * - - cpe:2.3:o:cisco:cbs250-8fp-e-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-16t-2g_firmware * - - cpe:2.3:o:cisco:cbs250-16t-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-16p-2g_firmware * - - cpe:2.3:o:cisco:cbs250-16p-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-24t-4g_firmware * - - cpe:2.3:o:cisco:cbs250-24t-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-24pp-4g_firmware * - - cpe:2.3:o:cisco:cbs250-24pp-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-24p-4g_firmware * - - cpe:2.3:o:cisco:cbs250-24p-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-24fp-4g_firmware * - - cpe:2.3:o:cisco:cbs250-24fp-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-48t-4g_firmware * - - cpe:2.3:o:cisco:cbs250-48t-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-48pp-4g_firmware * - - cpe:2.3:o:cisco:cbs250-48pp-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-48p-4g_firmware * - - cpe:2.3:o:cisco:cbs250-48p-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs250-24t-4x_firmware * - - cpe:2.3:o:cisco:cbs250-24t-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs250-24p-4x_firmware * - - cpe:2.3:o:cisco:cbs250-24p-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs250-24fp-4x_firmware * - - cpe:2.3:o:cisco:cbs250-24fp-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs250-48t-4x_firmware * - - cpe:2.3:o:cisco:cbs250-48t-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs250-48p-4x_firmware * - - cpe:2.3:o:cisco:cbs250-48p-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-8t-e-2g_firmware * - - cpe:2.3:o:cisco:cbs350-8t-e-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-8p-2g_firmware * - - cpe:2.3:o:cisco:cbs350-8p-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-8p-e-2g_firmware * - - cpe:2.3:o:cisco:cbs350-8p-e-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-8fp-2g_firmware * - - cpe:2.3:o:cisco:cbs350-8fp-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-8fp-e-2g_firmware * - - cpe:2.3:o:cisco:cbs350-8fp-e-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-8s-e-2g_firmware * - - cpe:2.3:o:cisco:cbs350-8s-e-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-16t-2g_firmware * - - cpe:2.3:o:cisco:cbs350-16t-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-16t-e-2g_firmware * - - cpe:2.3:o:cisco:cbs350-16t-e-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-16p-2g_firmware * - - cpe:2.3:o:cisco:cbs350-16p-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-16p-e-2g_firmware * - - cpe:2.3:o:cisco:cbs350-16p-e-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-16fp-2g_firmware * - - cpe:2.3:o:cisco:cbs350-16fp-2g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24t-4g_firmware * - - cpe:2.3:o:cisco:cbs350-24t-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24p-4g_firmware * - - cpe:2.3:o:cisco:cbs350-24p-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24fp-4g_firmware * - - cpe:2.3:o:cisco:cbs350-24fp-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24s-4g_firmware * - - cpe:2.3:o:cisco:cbs350-24s-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-48t-4g_firmware * - - cpe:2.3:o:cisco:cbs350-48t-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-48p-4g_firmware * - - cpe:2.3:o:cisco:cbs350-48p-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-48fp-4g_firmware * - - cpe:2.3:o:cisco:cbs350-48fp-4g_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24t-4x_firmware * - - cpe:2.3:o:cisco:cbs350-24t-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24p-4x_firmware * - - cpe:2.3:o:cisco:cbs350-24p-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24fp-4x_firmware * - - cpe:2.3:o:cisco:cbs350-24fp-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-48t-4x_firmware * - - cpe:2.3:o:cisco:cbs350-48t-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-48p-4x_firmware * - - cpe:2.3:o:cisco:cbs350-48p-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-48fp-4x_firmware * - - cpe:2.3:o:cisco:cbs350-48fp-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-8mgp-2x_firmware * - - cpe:2.3:o:cisco:cbs350-8mgp-2x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-8mp-2x_firmware * - - cpe:2.3:o:cisco:cbs350-8mp-2x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24mgp-4x_firmware * - - cpe:2.3:o:cisco:cbs350-24mgp-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-12np-4x_firmware * - - cpe:2.3:o:cisco:cbs350-12np-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24ngp-4x_firmware * - - cpe:2.3:o:cisco:cbs350-24ngp-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-48ngp-4x_firmware * - - cpe:2.3:o:cisco:cbs350-48ngp-4x_firmware:*:*:*:*:*:*:*:*
cisco cbs350-8xt_firmware * - - cpe:2.3:o:cisco:cbs350-8xt_firmware:*:*:*:*:*:*:*:*
cisco cbs350-12xs_firmware * - - cpe:2.3:o:cisco:cbs350-12xs_firmware:*:*:*:*:*:*:*:*
cisco cbs350-12xt_firmware * - - cpe:2.3:o:cisco:cbs350-12xt_firmware:*:*:*:*:*:*:*:*
cisco cbs350-16xts_firmware * - - cpe:2.3:o:cisco:cbs350-16xts_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24xs_firmware * - - cpe:2.3:o:cisco:cbs350-24xs_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24xt_firmware * - - cpe:2.3:o:cisco:cbs350-24xt_firmware:*:*:*:*:*:*:*:*
cisco cbs350-24xts_firmware * - - cpe:2.3:o:cisco:cbs350-24xts_firmware:*:*:*:*:*:*:*:*
cisco cbs350-48xt-4x_firmware * - - cpe:2.3:o:cisco:cbs350-48xt-4x_firmware:*:*:*:*:*:*:*:*
cisco sg350xg-2f10_firmware * - - cpe:2.3:o:cisco:sg350xg-2f10_firmware:*:*:*:*:*:*:*:*
cisco sg350xg-24f_firmware * - - cpe:2.3:o:cisco:sg350xg-24f_firmware:*:*:*:*:*:*:*:*
cisco sg350xg-24t_firmware * - - cpe:2.3:o:cisco:sg350xg-24t_firmware:*:*:*:*:*:*:*:*
cisco sg350xg-48t_firmware * - - cpe:2.3:o:cisco:sg350xg-48t_firmware:*:*:*:*:*:*:*:*
cisco sg350x-24_firmware * - - cpe:2.3:o:cisco:sg350x-24_firmware:*:*:*:*:*:*:*:*
cisco sg350x-24p_firmware * - - cpe:2.3:o:cisco:sg350x-24p_firmware:*:*:*:*:*:*:*:*
cisco sg350x-24mp_firmware * - - cpe:2.3:o:cisco:sg350x-24mp_firmware:*:*:*:*:*:*:*:*
cisco sg350x-48_firmware * - - cpe:2.3:o:cisco:sg350x-48_firmware:*:*:*:*:*:*:*:*
cisco sg350x-48p_firmware * - - cpe:2.3:o:cisco:sg350x-48p_firmware:*:*:*:*:*:*:*:*
cisco sg350x-48mp_firmware * - - cpe:2.3:o:cisco:sg350x-48mp_firmware:*:*:*:*:*:*:*:*
cisco sg550xg-8f8t_firmware * - - cpe:2.3:o:cisco:sg550xg-8f8t_firmware:*:*:*:*:*:*:*:*
cisco sg550xg-24f_firmware * - - cpe:2.3:o:cisco:sg550xg-24f_firmware:*:*:*:*:*:*:*:*
cisco sg550xg-24t_firmware * - - cpe:2.3:o:cisco:sg550xg-24t_firmware:*:*:*:*:*:*:*:*
cisco sg550x-48t_firmware * - - cpe:2.3:o:cisco:sg550x-48t_firmware:*:*:*:*:*:*:*:*
cisco sg550x-24_firmware * - - cpe:2.3:o:cisco:sg550x-24_firmware:*:*:*:*:*:*:*:*
cisco sg550x-24p_firmware * - - cpe:2.3:o:cisco:sg550x-24p_firmware:*:*:*:*:*:*:*:*
cisco sg550x-24mp_firmware * - - cpe:2.3:o:cisco:sg550x-24mp_firmware:*:*:*:*:*:*:*:*
cisco sg550x-24mpp_firmware * - - cpe:2.3:o:cisco:sg550x-24mpp_firmware:*:*:*:*:*:*:*:*
cisco sg550x-48_firmware * - - cpe:2.3:o:cisco:sg550x-48_firmware:*:*:*:*:*:*:*:*
cisco sg550x-48p_firmware * - - cpe:2.3:o:cisco:sg550x-48p_firmware:*:*:*:*:*:*:*:*
cisco sg550x-48mp_firmware * - - cpe:2.3:o:cisco:sg550x-48mp_firmware:*:*:*:*:*:*:*:*
cisco sf550x-24_firmware * - - cpe:2.3:o:cisco:sf550x-24_firmware:*:*:*:*:*:*:*:*
cisco sf550x-24p_firmware * - - cpe:2.3:o:cisco:sf550x-24p_firmware:*:*:*:*:*:*:*:*
cisco sf550x-24mp_firmware * - - cpe:2.3:o:cisco:sf550x-24mp_firmware:*:*:*:*:*:*:*:*
cisco sf550x-48_firmware * - - cpe:2.3:o:cisco:sf550x-48_firmware:*:*:*:*:*:*:*:*
cisco sf550x-48p_firmware * - - cpe:2.3:o:cisco:sf550x-48p_firmware:*:*:*:*:*:*:*:*
cisco sf550x-48mp_firmware * - - cpe:2.3:o:cisco:sf550x-48mp_firmware:*:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
cisco-sa-sb-bus-acl-bypass-5zn9hNJk OTHER
cve.org
访问
CVSS评分详情
3.1 (cna)
MEDIUM
5.8
CVSS向量: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
机密性
NONE
完整性
LOW
可用性
NONE
时间信息
发布时间:
2024-01-26 17:27:08
修改时间:
2024-11-13 14:55:13
创建时间:
2025-11-11 15:39:03
更新时间:
2025-11-11 15:58:27
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2024-20263 2025-11-11 15:22:23 2025-11-11 07:39:03
NVD nvd_CVE-2024-20263 2025-11-11 14:59:44 2025-11-11 07:47:04
CNNVD cnnvd_CNNVD-202401-2249 2025-11-11 15:11:27 2025-11-11 07:58:27
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN ZH
安全公告
暂无安全公告信息
变更历史
v3 CNNVD
2025-11-11 15:58:27
vulnerability_type: 未提取 → 其他; cnnvd_id: 未提取 → CNNVD-202401-2249; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 其他
  • cnnvd_id: 未提取 -> CNNVD-202401-2249
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:47:04
affected_products_count: 34 → 119; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • affected_products_count: 34 -> 119
  • data_sources: ['cve'] -> ['cve', 'nvd']