Junglewise Threat Intelligence

CVE-2023-20109: Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

CVE-2023-20109 · Severity: critical · CVSS 6.6 · Exploited in the wild · Published 2023-10-10

Technologies: Cisco IOS, Cisco IOS XE, Cisco IOS XR. Vendors: Cisco.

Executive brief

An out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS and IOS XE Software allows authenticated remote attackers with administrative control of a key server or group member to execute arbitrary code or cause a denial of service. The flaw stems from insufficient validation of attributes in the GDOI and G-IKEv2 protocols.

Affected products

  • Cisco IOS 12.4(22)md, 12.4(22)md1, 12.4(22)md2, 12.4(22)mda, 12.4(22)mda1
  • Cisco IOS XE

Timeline

  • 2023-10-10: disclosed
  • 2023-10-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-10-10: exploited: Reported as exploited in the wild at time of publication.

Related threats