Improper access control in Cisco Systems, Inc products - CVE-2024-20291
Published: February 29, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to incorrect hardware programming that occurs when configuration changes are made to port channel member ports. A remote attacker can send traffic that should be blocked through the affected device.
Affected software
Cisco Nexus 9000 Series Switches
Cisco NX-OS
PowerFlex Appliance
PowerFlex rack
How to mitigate CVE-2024-20291
PowerFlex Appliance - update to IC 45.374.00
PowerFlex rack - addressed in versions 3.6.6.0, 3.7.4.0