Vulnslist

find the latest Cisco vulnerabilities

CVE-2025-20339

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the improper enforcement of the implicit deny all at the end of a configured ACL. An attacker could exploit this vulnerability by attempting to send unauthorized traffic to an interface on an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device.

SeverityMEDIUM
CVSS5.8
CWECWE-284
KEV
Published
Modified

Related Products

Product Advisory
Cisco vEdge Routers cisco-sa-defaultacl-pSJk9nVF
Cisco SD-WAN cisco-sa-defaultacl-pSJk9nVF
Cisco Nexus Dashboard cisco-sa-defaultacl-pSJk9nVF
Cisco Catalyst SD-WAN Software cisco-sa-defaultacl-pSJk9nVF
Cisco SD-WAN vEdge Router cisco-sa-defaultacl-pSJk9nVF
Cisco SD-WAN vEdge Cloud cisco-sa-defaultacl-pSJk9nVF