CVE-2024-20291

MEDIUM
Published Feb 29, 2024 Modified Apr 30, 2025 CWE-284 CWE-863

Description

A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked through an affected device. This vulnerability is due to incorrect hardware programming that occurs when configuration changes are made to port channel member ports. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to access network resources that should be protected by an ACL that was applied on port channel subinterfaces.

Is your site exposed to CVE-2024-20291?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

5.8
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Weakness Type (CWE)

CWE-284 CWE-284
CWE-863 Incorrect Authorization

Affected Products

Vendor Product
cisco nx-os
cisco nx-os
cisco nx-os
cisco nexus_3000_in_standalone_nx-os_mode
cisco nexus_3048
cisco nexus_31108pc-v
cisco nexus_31108tc-v
cisco nexus_31128pq
cisco nexus_3132c-z
cisco nexus_3132q-v
cisco nexus_3132q-xl
cisco nexus_3164q
cisco nexus_3172pq
cisco nexus_3172pq-xl
cisco nexus_3172tq
cisco nexus_3172tq-32t
cisco nexus_3172tq-xl
cisco nexus_3232c
cisco nexus_3264c-e
cisco nexus_3264q
cisco nexus_3408-s
cisco nexus_34180yc
cisco nexus_34200yc-sm
cisco nexus_3432d-s
cisco nexus_3464c
cisco nexus_3524-x
cisco nexus_3524-xl
cisco nexus_3548-x
cisco nexus_3548-xl
cisco nexus_36180yc-r
cisco nexus_9000_in_standalone_nx-os_mode
cisco nexus_9000v
cisco nexus_92160yc-x
cisco nexus_92300yc
cisco nexus_92304qc
cisco nexus_92348gc-fx3
cisco nexus_92348gc-x
cisco nexus_9236c
cisco nexus_9272q
cisco nexus_93108tc-ex
cisco nexus_93108tc-ex-24
cisco nexus_93108tc-fx
cisco nexus_93108tc-fx-24
cisco nexus_93108tc-fx3
cisco nexus_93108tc-fx3h
cisco nexus_93108tc-fx3p
cisco nexus_93120tx
cisco nexus_9316d-gx
cisco nexus_93180lc-ex
cisco nexus_93180yc-ex
cisco nexus_93180yc-ex-24
cisco nexus_93180yc-fx
cisco nexus_93180yc-fx-24
cisco nexus_93180yc-fx3
cisco nexus_93180yc-fx3h
cisco nexus_93180yc-fx3s
cisco nexus_93216tc-fx2
cisco nexus_93240yc-fx2
cisco nexus_9332c
cisco nexus_9332d-gx2b
cisco nexus_9332d-h2r
cisco nexus_9332pq
cisco nexus_93360yc-fx2
cisco nexus_9336c-fx2
cisco nexus_9336c-fx2-e
cisco nexus_9336pq_aci_spine
cisco nexus_93400ld-h1
cisco nexus_9348d-gx2a
cisco nexus_9348gc-fx3
cisco nexus_9348gc-fxp
cisco nexus_93600cd-gx
cisco nexus_9364c
cisco nexus_9364c-gx
cisco nexus_9364c-h1
cisco nexus_9364d-gx2a
cisco nexus_9364e-sg2
cisco nexus_9372px-e
cisco nexus_9372tx-e
cisco nexus_9396tx
cisco nexus_9408
cisco nexus_9508
cisco nexus_9804
cisco nexus_9808

References

Frequently Asked Questions

What is CVE-2024-20291? +
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked through an affected device. This vulnerability is due to incorrect hardware programming that occurs when configuration changes are made to port channel member ports. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to access network resources that should be protected by an ACL that was applied on port channel subinterfaces. It has a CVSS v3.1 base score of 5.8 (MEDIUM).
How severe is CVE-2024-20291? +
CVE-2024-20291 has a CVSS v3.1 score of 5.8 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-20291? +
CVE-2024-20291 affects products from cisco, specifically: nexus_3000_in_standalone_nx-os_mode, nexus_3048, nexus_31108pc-v, nexus_31108tc-v, nexus_31128pq, nexus_3132c-z, nexus_3132q-v, nexus_3132q-xl, nexus_3164q, nexus_3172pq, nexus_3172pq-xl, nexus_3172tq, nexus_3172tq-32t, nexus_3172tq-xl, nexus_3232c, nexus_3264c-e, nexus_3264q, nexus_3408-s, nexus_34180yc, nexus_34200yc-sm, nexus_3432d-s, nexus_3464c, nexus_3524-x, nexus_3524-xl, nexus_3548-x, nexus_3548-xl, nexus_36180yc-r, nexus_9000_in_standalone_nx-os_mode, nexus_9000v, nexus_92160yc-x, nexus_92300yc, nexus_92304qc, nexus_92348gc-fx3, nexus_92348gc-x, nexus_9236c, nexus_9272q, nexus_93108tc-ex, nexus_93108tc-ex-24, nexus_93108tc-fx, nexus_93108tc-fx-24, nexus_93108tc-fx3, nexus_93108tc-fx3h, nexus_93108tc-fx3p, nexus_93120tx, nexus_9316d-gx, nexus_93180lc-ex, nexus_93180yc-ex, nexus_93180yc-ex-24, nexus_93180yc-fx, nexus_93180yc-fx-24, nexus_93180yc-fx3, nexus_93180yc-fx3h, nexus_93180yc-fx3s, nexus_93216tc-fx2, nexus_93240yc-fx2, nexus_9332c, nexus_9332d-gx2b, nexus_9332d-h2r, nexus_9332pq, nexus_93360yc-fx2, nexus_9336c-fx2, nexus_9336c-fx2-e, nexus_9336pq_aci_spine, nexus_93400ld-h1, nexus_9348d-gx2a, nexus_9348gc-fx3, nexus_9348gc-fxp, nexus_93600cd-gx, nexus_9364c, nexus_9364c-gx, nexus_9364c-h1, nexus_9364d-gx2a, nexus_9364e-sg2, nexus_9372px-e, nexus_9372tx-e, nexus_9396tx, nexus_9408, nexus_9508, nexus_9804, nexus_9808, nx-os. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-20291? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-20291 — free, no signup required.