peter bassill · operator
$ cve CVE-2023-20109 JSON

CVE-2023-20109 KEV

6.6
MEDIUM · CVSS 3.1 · EPSS 2.3% (pctl 83)

Patch first

On CISA KEV — known exploited in the wild, due 2023-10-31.

Description

A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a denial of service (DoS) condition. For more information, see the Details ["#details"] section of this advisory.

Scoring

CVSS6.6 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS2.34% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2023-10-31
Public exploitnone known
Published2023-09-27
Last modified2026-06-17

CISA KEV

NameCisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
Added2023-10-10
Due2023-10-31
Vendor / productCisco / IOS and IOS XE
Ransomware usenone reported

Affected (2)

VendorProduct
ciscoios
ciscoios xe

References

→ the Explorer  ·  watch your stack  ·  NVD