Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2024-20510

A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication. This vulnerability is due to a logic error when activating the pre-authentication ACL that is received from the authentication, authorization, and accounting (AAA) server. An attacker could exploit this vulnerability by connecting to a wireless network that is configured for CWA and sending traffic through an affected device that should be denied by the configured ACL before user authentication. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device before the user authentication is completed, allowing the attacker to access trusted networks that the device might be protecting.

SeverityMEDIUM
CVSS4.7
CWECWE-863
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco IOS cisco-sa-c9800-cwa-acl-nPSbHSnA Cisco OpenVuln
Cisco IOS XE Software cisco-sa-c9800-cwa-acl-nPSbHSnA Cisco OpenVuln
Cisco Catalyst 9600 Series Switches cisco-sa-c9800-cwa-acl-nPSbHSnA Cisco OpenVuln · software-dependent
Cisco Catalyst 9500 Series Switches cisco-sa-c9800-cwa-acl-nPSbHSnA Cisco OpenVuln · software-dependent
Cisco Catalyst 9400 Series Switches cisco-sa-c9800-cwa-acl-nPSbHSnA Cisco OpenVuln · software-dependent
Cisco Catalyst 9200 Series Switches cisco-sa-c9800-cwa-acl-nPSbHSnA Cisco OpenVuln · software-dependent
Cisco Catalyst 9300 Series Switches cisco-sa-c9800-cwa-acl-nPSbHSnA Cisco OpenVuln · software-dependent