A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 1000 Switches and Cisco Catalyst 2960L Switches could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the use of both an IPv4 ACL and a dynamic ACL of IP Source Guard on the same interface, which is an unsupported configuration. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device. Note: Cisco documentation has been updated to reflect that this is an unsupported configuration. However, Cisco is publishing this advisory because the device will not prevent an administrator from configuring both features on the same interface. There are no plans to implement the ability to configure both features on the same interface on Cisco Catalyst 1000 or Catalyst 2960L Switches.
History

Tue, 05 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco catalyst 1000-16fp-2g-l
Cisco catalyst 1000-16p-2g-l
Cisco catalyst 1000-16t-2g-l
Cisco catalyst 1000-16t-e-2g-l
Cisco catalyst 1000-24fp-4g-l
Cisco catalyst 1000-24fp-4x-l
Cisco catalyst 1000-24p-4g-l
Cisco catalyst 1000-24p-4x-l
Cisco catalyst 1000-24pp-4g-l
Cisco catalyst 1000-24t-4g-l
Cisco catalyst 1000-24t-4x-l
Cisco catalyst 1000-48fp-4g-l
Cisco catalyst 1000-48fp-4x-l
Cisco catalyst 1000-48p-4g-l
Cisco catalyst 1000-48p-4x-l
Cisco catalyst 1000-48pp-4g-l
Cisco catalyst 1000-48t-4g-l
Cisco catalyst 1000-48t-4x-l
Cisco catalyst 1000-8fp-2g-l
Cisco catalyst 1000-8fp-e-2g-l
Cisco catalyst 1000-8p-2g-l
Cisco catalyst 1000-8p-e-2g-l
Cisco catalyst 1000-8t-2g-l
Cisco catalyst 1000-8t-e-2g-l
Cisco catalyst 1000fe-24p-4g-l
Cisco catalyst 1000fe-24t-4g-l
Cisco catalyst 1000fe-48p-4g-l
Cisco catalyst 1000fe-48t-4g-l
Cisco catalyst 2960l-16ps-ll
Cisco catalyst 2960l-16ts-ll
Cisco catalyst 2960l-24pq-ll
Cisco catalyst 2960l-24ps-ll
Cisco catalyst 2960l-24tq-ll
Cisco catalyst 2960l-24ts-ll
Cisco catalyst 2960l-48pq-ll
Cisco catalyst 2960l-48ps-ll
Cisco catalyst 2960l-48tq-ll
Cisco catalyst 2960l-48ts-ll
Cisco catalyst 2960l-8ps-ll
Cisco catalyst 2960l-8ts-ll
Cisco ios
CPEs cpe:2.3:h:cisco:catalyst_1000-16fp-2g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-16p-2g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-16t-2g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-16t-e-2g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-24fp-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-24fp-4x-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-24p-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-24p-4x-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-24pp-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-24t-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-24t-4x-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-48fp-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-48fp-4x-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-48p-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-48p-4x-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-48pp-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-48t-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-48t-4x-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-8fp-2g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-8fp-e-2g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-8p-2g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-8p-e-2g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-8t-2g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000-8t-e-2g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000fe-24p-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000fe-24t-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000fe-48p-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_1000fe-48t-4g-l:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-16ps-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-16ts-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-24pq-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-24ps-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-24tq-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-24ts-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-48pq-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-48ps-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-48tq-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-48ts-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-8ps-ll:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:catalyst_2960l-8ts-ll:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(5a\)e:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(5b\)e:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(5c\)e:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(6\)e0c:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(6\)e1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(6\)e2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(6\)e2b:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(6\)e3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(6\)e:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e0a:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e0s:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e10:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e11:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e12:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e1a:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e3k:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e4:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e5:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e6:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e7:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e8:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e9:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7\)e:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7a\)e0b:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(7b\)e0b:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(8\)e1:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(8\)e2:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(8\)e3:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(8\)e4:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(8\)e5:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(8\)e6:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2\(8\)e:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco catalyst 1000-16fp-2g-l
Cisco catalyst 1000-16p-2g-l
Cisco catalyst 1000-16t-2g-l
Cisco catalyst 1000-16t-e-2g-l
Cisco catalyst 1000-24fp-4g-l
Cisco catalyst 1000-24fp-4x-l
Cisco catalyst 1000-24p-4g-l
Cisco catalyst 1000-24p-4x-l
Cisco catalyst 1000-24pp-4g-l
Cisco catalyst 1000-24t-4g-l
Cisco catalyst 1000-24t-4x-l
Cisco catalyst 1000-48fp-4g-l
Cisco catalyst 1000-48fp-4x-l
Cisco catalyst 1000-48p-4g-l
Cisco catalyst 1000-48p-4x-l
Cisco catalyst 1000-48pp-4g-l
Cisco catalyst 1000-48t-4g-l
Cisco catalyst 1000-48t-4x-l
Cisco catalyst 1000-8fp-2g-l
Cisco catalyst 1000-8fp-e-2g-l
Cisco catalyst 1000-8p-2g-l
Cisco catalyst 1000-8p-e-2g-l
Cisco catalyst 1000-8t-2g-l
Cisco catalyst 1000-8t-e-2g-l
Cisco catalyst 1000fe-24p-4g-l
Cisco catalyst 1000fe-24t-4g-l
Cisco catalyst 1000fe-48p-4g-l
Cisco catalyst 1000fe-48t-4g-l
Cisco catalyst 2960l-16ps-ll
Cisco catalyst 2960l-16ts-ll
Cisco catalyst 2960l-24pq-ll
Cisco catalyst 2960l-24ps-ll
Cisco catalyst 2960l-24tq-ll
Cisco catalyst 2960l-24ts-ll
Cisco catalyst 2960l-48pq-ll
Cisco catalyst 2960l-48ps-ll
Cisco catalyst 2960l-48tq-ll
Cisco catalyst 2960l-48ts-ll
Cisco catalyst 2960l-8ps-ll
Cisco catalyst 2960l-8ts-ll
Cisco ios

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00049}

epss

{'score': 0.00052}


Wed, 07 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 17:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 1000 Switches and Cisco Catalyst 2960L Switches could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the use of both an IPv4 ACL and a dynamic ACL of IP Source Guard on the same interface, which is an unsupported configuration. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to bypass an ACL on the affected device. Note: Cisco documentation has been updated to reflect that this is an unsupported configuration. However, Cisco is publishing this advisory because the device will not prevent an administrator from configuring both features on the same interface. There are no plans to implement the ability to configure both features on the same interface on Cisco Catalyst 1000 or Catalyst 2960L Switches.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2025-05-07T17:31:45.590Z

Updated: 2025-05-07T19:45:55.934Z

Reserved: 2024-10-10T19:15:13.213Z

Link: CVE-2025-20137

cve-icon Vulnrichment

Updated: 2025-05-07T18:56:19.336Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-07T18:15:36.473

Modified: 2025-08-05T14:08:32.490

Link: CVE-2025-20137

cve-icon Redhat

No data.