7.2
CWE
284
EPSS
0.063%
Advisory Published
Updated

CVE-2024-20263

First published: Fri Jan 26 2024(Updated: )

A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series Managed Switches could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device. This vulnerability is due to incorrect processing of ACLs on a stacked configuration when either the primary or backup switches experience a full stack reload or power cycle. An attacker could exploit this vulnerability by sending crafted traffic through an affected device. A successful exploit could allow the attacker to bypass configured ACLs, causing traffic to be dropped or forwarded in an unexpected manner. The attacker does not have control over the conditions that result in the device being in the vulnerable state. Note: In the vulnerable state, the ACL would be correctly applied on the primary devices but could be incorrectly applied to the backup devices.

Credit: ykramarz@cisco.com

Affected SoftwareAffected VersionHow to fix
All of
Cisco CBS250-8T-D Firmware>=3.4<3.4.0.17
Cisco CBS250-8T-D Firmware
All of
Cisco CBS250-8PP-D>=3.4<3.4.0.17
Cisco CBS250-8PP-D
All of
Cisco CBS250-8T-E-2G Firmware>=3.4<3.4.0.17
Cisco CBS250-8T-E-2G Firmware
All of
Cisco CBS250-8PP-E-2G Firmware>=3.4<3.4.0.17
Cisco CBS250-8PP-E-2G Firmware
All of
Cisco cbs250-8p-e-2g firmware>=3.4<3.4.0.17
Cisco CBS250-8P-E-2G
All of
Cisco CBS250-8FP-E-2G>=3.4<3.4.0.17
Cisco cbs250-8fp-e-2g firmware
All of
Cisco CBS250-16T-2G Firmware>=3.4<3.4.0.17
Cisco CBS250-16T-2G
All of
Cisco CBS250-16P-2G>=3.4<3.4.0.17
Cisco cbs250-16p-2g firmware
All of
Cisco CBS250-24T-4G Firmware>=3.4<3.4.0.17
Cisco CBS250-24T-4G
All of
Cisco CBS250-24PP-4G Firmware>=3.4<3.4.0.17
Cisco CBS250-24PP-4G
All of
Cisco CBS250-24P-4G Firmware>=3.4<3.4.0.17
Cisco CBS250-24P-4G Firmware
All of
Cisco CBS250-24FP-4G Firmware>=3.4<3.4.0.17
Cisco CBS250-24FP-4X
All of
Cisco CBS250-48T-4G Firmware>=3.4<3.4.0.17
Cisco CBS250-48T-4G
All of
Cisco CBS250-48PP-4G Firmware>=3.4<3.4.0.17
Cisco CBS250-48PP-4G
All of
Cisco CBS250-48P-4G Firmware>=3.4<3.4.0.17
Cisco CBS250-48P-4G Firmware
All of
Cisco CBS250-24T-4X Firmware>=3.4<3.4.0.17
Cisco CBS250-24T-4X Firmware
All of
Cisco CBS250-24P-4X Firmware>=3.4<3.4.0.17
Cisco CBS250-24P-4X
All of
Cisco CBS250-24FP-4X Firmware>=3.4<3.4.0.17
Cisco CBS250-24FP-4X
All of
Cisco CBS250-48T-4X Firmware>=3.4<3.4.0.17
Cisco CBS250-48T-4X
All of
Cisco CBS250-48P-4X>=3.4<3.4.0.17
Cisco CBS250-48P-4X
All of
Cisco CBS350-8T-E-2G Firmware>=3.4<3.4.0.17
Cisco CBS350-8T-E-2G Firmware
All of
Cisco CBS350-8P-2G Firmware>=3.4<3.4.0.17
Cisco CBS350-8P-2G Firmware
All of
Cisco cbs350-8p-e-2g firmware>=3.4<3.4.0.17
Cisco cbs350-8p-e-2g firmware
All of
Cisco CBS350-8FP-2G Firmware>=3.4<3.4.0.17
Cisco CBS350-8FP-2G Firmware
All of
Cisco CBS350-8FP-E-2G Firmware>=3.4<3.4.0.17
Cisco CBS350-8FP-E-2G Firmware
All of
Cisco CBS350-8S-E-2G>=3.4<3.4.0.17
Cisco CBS350-8S-E-2G
All of
Cisco CBS350-16T-2G Firmware>=3.4<3.4.0.17
Cisco CBS350-16T-2G Firmware
All of
Cisco CBS350-16T-E-2G>=3.4<3.4.0.17
Cisco CBS350-16T-E-2G
All of
Cisco CBS350-16P-2G>=3.4<3.4.0.17
Cisco CBS350-16P-2G
All of
Cisco CBS350-16P-E-2G Firmware>=3.4<3.4.0.17
Cisco CBS350-16P-E-2G Firmware
All of
Cisco CBS350-16FP-2G Firmware>=3.4<3.4.0.17
Cisco CBS350-16FP-2G Firmware
All of
Cisco CBS350-24T-4G Firmware>=3.4<3.4.0.17
Cisco CBS350-24T-4G
All of
Cisco CBS350-24P-4G Firmware>=3.4<3.4.0.17
Cisco CBS350-24P-4G Firmware
All of
Cisco CBS350-24FP-4G Firmware>=3.4<3.4.0.17
Cisco CBS350-24FP-4G
All of
Cisco CBS350-24S-4G Firmware>=3.4<3.4.0.17
Cisco CBS350-24S-4G
All of
Cisco CBS350-48T-4G Firmware>=3.4<3.4.0.17
Cisco CBS350-48T-4G
All of
Cisco CBS350-48P-4G>=3.4<3.4.0.17
Cisco CBS350-48P-4G
All of
Cisco CBS350-48FP-4G Firmware>=3.4<3.4.0.17
Cisco CBS350-48FP-4G Firmware
All of
Cisco cbs350-24t-4x firmware>=3.4<3.4.0.17
Cisco CBS350-24T-4X
All of
Cisco CBS350-24P-4X Firmware>=3.4<3.4.0.17
Cisco CBS350-24P-4X
All of
Cisco CBS350-24FP-4X Firmware>=3.4<3.4.0.17
Cisco CBS350-24FP-4X
All of
Cisco CBS350-48T-4X Firmware>=3.4<3.4.0.17
Cisco CBS350-48T-4X Firmware
All of
Cisco CBS350-48P-4X Firmware>=3.4<3.4.0.17
Cisco CBS350-48P-4X
All of
Cisco CBS350-48FP-4X>=3.4<3.4.0.17
Cisco CBS350-48FP-4X
All of
Cisco CBS350-8MG-2X Firmware>=3.4<3.4.0.17
Cisco CBS350-8MG-2X Firmware
All of
Cisco CBS350-8MG-2X Firmware>=3.4<3.4.0.17
Cisco CBS350-8MG-2X Firmware
All of
Cisco CBS350-24MGPA-4X Firmware>=3.4<3.4.0.17
Cisco CBS350-24MG-4X
All of
Cisco CBS350-12NP-4X>=3.4<3.4.0.17
Cisco CBS350-12NP-4X
All of
Cisco CBS350-24NGP-4X Firmware>=3.4<3.4.0.17
Cisco CBS350-24NGP-4X Firmware
All of
Cisco CBS350-48NGP-4X Firmware>=3.4<3.4.0.17
Cisco CBS350-48NGP-4X Firmware
All of
Cisco CBS350-8XT Firmware>=3.4<3.4.0.17
Cisco CBS350-8XT
All of
Cisco CBS350-12XS Firmware>=3.4<3.4.0.17
Cisco CBS350-12XS Firmware
All of
Cisco CBS350-12XT Firmware>=3.4<3.4.0.17
Cisco CBS350-12XT Firmware
All of
Cisco CBS350-16XTS Firmware>=3.4<3.4.0.17
Cisco CBS350-16XT
All of
Cisco CBS350-24XS Firmware>=3.4<3.4.0.17
Cisco CBS350-24XS
All of
Cisco CBS350-24XT Firmware>=3.4<3.4.0.17
Cisco CBS350-24XT Firmware
All of
Cisco CBS350-24XT>=3.4<3.4.0.17
Cisco CBS350-24XT
All of
Cisco CBS350-48XT-4X Firmware>=3.4<3.4.0.17
Cisco CBS350-48XT-4X Firmware
All of
Cisco CBS250-8T-D Firmware>=2.5<2.5.9.54
Cisco CBS250-8T-D Firmware
All of
Cisco CBS250-8PP-D>=2.5<2.5.9.54
Cisco CBS250-8PP-D
All of
Cisco CBS250-8T-E-2G Firmware>=2.5<2.5.9.54
Cisco CBS250-8T-E-2G Firmware
All of
Cisco CBS250-8PP-E-2G Firmware>=2.5<2.5.9.54
Cisco CBS250-8PP-E-2G Firmware
All of
Cisco cbs250-8p-e-2g firmware>=2.5<2.5.9.54
Cisco CBS250-8P-E-2G
All of
Cisco CBS250-8FP-E-2G>=2.5<2.5.9.54
Cisco cbs250-8fp-e-2g firmware
All of
Cisco CBS250-16T-2G Firmware>=2.5<=2.5.9.54
Cisco CBS250-16T-2G
All of
Cisco CBS250-16P-2G>=2.5<2.5.9.54
Cisco cbs250-16p-2g firmware
All of
Cisco CBS250-24T-4G Firmware>=2.5<2.5.9.54
Cisco CBS250-24T-4G
All of
Cisco CBS250-24PP-4G Firmware>=2.5<2.5.9.54
Cisco CBS250-24PP-4G
All of
Cisco CBS250-24P-4G Firmware>=2.5<2.5.9.54
Cisco CBS250-24P-4G Firmware
All of
Cisco CBS250-24FP-4G Firmware>=2.5<2.5.9.54
Cisco CBS250-24FP-4X
All of
Cisco CBS250-48T-4G Firmware>=2.5<2.5.9.54
Cisco CBS250-48T-4G
All of
Cisco CBS250-48PP-4G Firmware>=2.5<2.5.9.54
Cisco CBS250-48PP-4G
All of
Cisco CBS250-48P-4G Firmware>=2.5<2.5.9.54
Cisco CBS250-48P-4G Firmware
All of
Cisco CBS250-24T-4X Firmware>=2.5<2.5.9.54
Cisco CBS250-24T-4X Firmware
All of
Cisco CBS250-24P-4X Firmware>=2.5<2.5.9.54
Cisco CBS250-24P-4X
All of
Cisco CBS250-24FP-4X Firmware>=2.5<2.5.9.54
Cisco CBS250-24FP-4X
All of
Cisco CBS250-48T-4X Firmware>=2.5<2.5.9.54
Cisco CBS250-48T-4X
All of
Cisco CBS250-48P-4X>=2.5<2.5.9.54
Cisco CBS250-48P-4X
All of
Cisco CBS350-8T-E-2G Firmware>=2.5<2.5.9.54
Cisco CBS350-8T-E-2G Firmware
All of
Cisco CBS350-8P-2G Firmware>=2.5<2.5.9.54
Cisco CBS350-8P-2G Firmware
All of
Cisco cbs350-8p-e-2g firmware>=2.5<2.5.9.54
Cisco cbs350-8p-e-2g firmware
All of
Cisco CBS350-8FP-2G Firmware>=2.5<2.5.9.54
Cisco CBS350-8FP-2G Firmware
All of
Cisco CBS350-8FP-E-2G Firmware>=2.5<2.5.9.54
Cisco CBS350-8FP-E-2G Firmware
All of
Cisco CBS350-8S-E-2G>=2.5<2.5.9.54
Cisco CBS350-8S-E-2G
All of
Cisco CBS350-16T-2G Firmware>=2.5<2.5.9.54
Cisco CBS350-16T-2G Firmware
All of
Cisco CBS350-16T-E-2G>=2.5<2.5.9.54
Cisco CBS350-16T-E-2G
All of
Cisco CBS350-16P-2G>=2.5<2.5.9.54
Cisco CBS350-16P-2G
All of
Cisco CBS350-16P-E-2G Firmware>=2.5<2.5.9.54
Cisco CBS350-16P-E-2G Firmware
All of
Cisco CBS350-16FP-2G Firmware>=2.5<2.5.9.54
Cisco CBS350-16FP-2G Firmware
All of
Cisco CBS350-24T-4G Firmware>=2.5<2.5.9.54
Cisco CBS350-24T-4G
All of
Cisco CBS350-24P-4G Firmware>=2.5<2.5.9.54
Cisco CBS350-24P-4G Firmware
All of
Cisco CBS350-24FP-4G Firmware>=2.5<2.5.9.54
Cisco CBS350-24FP-4G
All of
Cisco CBS350-24S-4G Firmware>=2.5<2.5.9.54
Cisco CBS350-24S-4G
All of
Cisco CBS350-48T-4G Firmware>=2.5<2.5.9.54
Cisco CBS350-48T-4G
All of
Cisco CBS350-48P-4G>=2.5<2.5.9.54
Cisco CBS350-48P-4G
All of
Cisco CBS350-48FP-4G Firmware>=2.5<2.5.9.54
Cisco CBS350-48FP-4G Firmware
All of
Cisco cbs350-24t-4x firmware>=2.5<2.5.9.54
Cisco CBS350-24T-4X
All of
Cisco CBS350-24P-4X Firmware>=2.5<2.5.9.54
Cisco CBS350-24P-4X
All of
Cisco CBS350-24FP-4X Firmware>=2.5<2.5.9.54
Cisco CBS350-24FP-4X
All of
Cisco CBS350-48T-4X Firmware>=2.5<2.5.9.54
Cisco CBS350-48T-4X Firmware
All of
Cisco CBS350-48P-4X Firmware>=2.5<2.5.9.54
Cisco CBS350-48P-4X
All of
Cisco CBS350-48FP-4X>=2.5<2.5.9.54
Cisco CBS350-48FP-4X
All of
Cisco CBS350-8MG-2X Firmware>=2.5<2.5.9.54
Cisco CBS350-8MG-2X Firmware
All of
Cisco CBS350-8MG-2X Firmware>=2.5<2.5.9.54
Cisco CBS350-8MG-2X Firmware
All of
Cisco CBS350-24MGPA-4X Firmware>=2.5<2.5.9.54
Cisco CBS350-24MG-4X
All of
Cisco CBS350-12NP-4X>=2.5<2.5.9.54
Cisco CBS350-12NP-4X
All of
Cisco CBS350-24NGP-4X Firmware>=2.5<2.5.9.54
Cisco CBS350-24NGP-4X Firmware
All of
Cisco CBS350-48NGP-4X Firmware>=2.5<2.5.9.54
Cisco CBS350-48NGP-4X Firmware
All of
Cisco CBS350-8XT Firmware>=2.5<2.5.9.54
Cisco CBS350-8XT
All of
Cisco CBS350-12XS Firmware>=2.5<2.5.9.54
Cisco CBS350-12XS Firmware
All of
Cisco CBS350-12XT Firmware>=2.5<2.5.9.54
Cisco CBS350-12XT Firmware
All of
Cisco CBS350-16XTS Firmware>=2.5<2.5.9.54
Cisco CBS350-16XT
All of
Cisco CBS350-24XS Firmware>=2.5<2.5.9.54
Cisco CBS350-24XS
All of
Cisco CBS350-24XT Firmware>=2.5<2.5.9.54
Cisco CBS350-24XT Firmware
All of
Cisco CBS350-24XT>=2.5<2.5.9.54
Cisco CBS350-24XT
All of
Cisco CBS350-48XT-4X Firmware>=2.5<2.5.9.54
Cisco CBS350-48XT-4X Firmware
All of
Cisco SG350XG-2F10 Firmware>=2.5<2.5.9.54
Cisco SG350XG-2F10
All of
Cisco SG350XG-24F Firmware>=2.5<2.5.9.54
Cisco SG350XG-24F Firmware
All of
Cisco SG350XG-24T Firmware>=2.5<2.5.9.54
Cisco SG350XG-24T Firmware
All of
Cisco SG350XG-48T Firmware>=2.5<2.5.9.54
Cisco SG350XG-48T Firmware
All of
Cisco SG350X-24 Firmware>=2.5<2.5.9.54
Cisco SG350X-24 Firmware
All of
Cisco SG350X-24 Firmware>=2.5<2.5.9.54
Cisco SG350X-24PV
All of
Cisco SG350X-24MP Firmware>=2.5<2.5.9.54
Cisco SG350X-24MP
All of
Cisco SG350X-48 Firmware>=2.5<2.5.9.54
Cisco SG350X-48
All of
Cisco SG350X-48P Firmware>=2.5<2.5.9.54
Cisco SG350X-48P Firmware
All of
Cisco SG350X-48MP Firmware>=2.5<2.5.9.54
Cisco SG350X-48MP Firmware
All of
Cisco SG550XG-8F8T firmware>=2.5<2.5.9.54
Cisco SG500XG-8F8T Firmware
All of
Cisco SG550XG-24F Firmware>=2.5<2.5.9.54
Cisco SG550XG-24F
All of
Cisco SG550XG-24T>=2.5<2.5.9.54
Cisco SG550XG-24T
All of
Cisco SG550X-48T Firmware>=2.5<2.5.9.54
Cisco SG550X-48T Firmware
All of
Cisco SG550X-24 Firmware>=2.5<2.5.9.54
Cisco SG550X-24 Firmware
All of
Cisco SG550X-24P Firmware>=2.5<2.5.9.54
Cisco SG550X-24P Firmware
All of
Cisco SG550X-24MP Firmware>=2.5<2.5.9.54
Cisco SG550X-24MP
All of
Cisco SG550X-24MPP Firmware>=2.5<2.5.9.54
Cisco SG550X-24MPP
All of
Cisco SG550X-48MP Firmware>=2.5<2.5.9.54
Cisco SG550X-48T
All of
Cisco SG550X-48P Firmware>=2.5<2.5.9.54
Cisco SG550X-48P
All of
Cisco SG550X-48MP Firmware>=2.5<2.5.9.54
Cisco SG550X-48MP
All of
Cisco SF550X-24 Firmware>=2.5<2.5.9.54
Cisco SF550X-24 Firmware
All of
Cisco SF550X-24P Firmware>=2.5<2.5.9.54
Cisco SF550X-24P
All of
Cisco SF550X-24MP Firmware>=2.5<2.5.9.54
Cisco SF550X-24MP
All of
Cisco SF550X-48 Firmware>=2.5<2.5.9.54
Cisco SF550X-48
All of
Cisco SF550X-48P Firmware>=2.5<2.5.9.54
Cisco SG550X-48P
All of
Cisco SG550X-48MP Firmware>=2.5<2.5.9.54
Cisco SF550X-48MP

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-20263?

    CVE-2024-20263 has a severity rating of high, indicating that it poses a significant risk to vulnerable systems.

  • How do I fix CVE-2024-20263?

    To fix CVE-2024-20263, upgrade the firmware of affected Cisco Business 250 Series and 350 Series switches to versions above 3.4.0.17.

  • What devices are affected by CVE-2024-20263?

    CVE-2024-20263 affects Cisco Business 250 Series and 350 Series Managed Switches with certain firmware versions.

  • Can CVE-2024-20263 be exploited remotely?

    Yes, CVE-2024-20263 can be exploited by an unauthenticated remote attacker.

  • What does CVE-2024-20263 specifically allow attackers to do?

    CVE-2024-20263 allows attackers to bypass access controls established by configured ACLs on affected devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203