Executive brief
An out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS and IOS XE Software allows authenticated remote attackers with administrative control of a key server or group member to execute arbitrary code or cause a denial of service. The flaw stems from insufficient validation of attributes in the GDOI and G-IKEv2 protocols.
Affected products
- Cisco IOS 12.4(22)md, 12.4(22)md1, 12.4(22)md2, 12.4(22)mda, 12.4(22)mda1
- Cisco IOS XE
Timeline
- 2023-10-10: disclosed
- 2023-10-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-10-10: exploited: Reported as exploited in the wild at time of publication.