Record summary

CVE-2023-20109 has a selected CVSS score of 6.6 (medium). CISA lists CVE-2023-20109 in KEV.

Description

A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a denial of service (DoS) condition. For more information, see the Details ["#details"] section of this advisory.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Oct 10, 2023 · CISA
VulnCheck KEV
Listed · Sep 27, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 23, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
CVE List3.7.0Saffected
3.7.1Saffected
3.7.2Saffected
3.7.3Saffected
3.7.4Saffected
3.7.5Saffected
3.7.6Saffected
3.7.7Saffected
3.7.4aSaffected
3.7.2tSaffected
3.7.0bSaffected
3.7.1aSaffected
Showing 12 of 364 version ranges
CVE List12.4(24)Taffected
12.4(24)T3affected
12.4(22)T1affected
12.4(24)T5affected
12.4(24)T4affected
12.4(22)Taffected
12.4(24)T8affected
12.4(24)T2affected
12.4(22)T5affected
12.4(22)T4affected
12.4(24)T1affected
12.4(24)T7affected
Showing 12 of 674 version ranges
CISAVersion data not supplied
VulnCheckVersion data not supplied

References

3