CVE-2023-20109
Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
Description
CVE-2023-20109 is a medium-severity out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software. The vulnerability allows an authenticated, remote attacker who already has administrative control of a group member or key server to execute arbitrary code or cause a denial of service on affected devices. This out-of-bounds write flaw stems from insufficient validation of attributes in the GDOI and G-IKEv2 protocols used by the GET VPN feature. CISA has added CVE-2023-20109 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, though the EPSS score of 0.58% suggests exploitation is targeted rather than widespread.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| cisco | ios | 12.4\(22\)md; 12.4\(22\)md1; 12.4\(22\)md2; 12.4\(22\)mda; 12.4\(22\)mda1; 12.4\(22\)mda2; 12.4\(22\)mda3; 12.4\(22\)mda4; 12.4\(22\)mda5; 12.4\(22\)mda6; 12.4\(22\)t; 12.4\(22\)t1; 12.4\(22\)t2; 12.4\(22\)t3; 12.4\(22\)t4; 12.4\(22\)t5; 12.4\(22\)xr1; 12.4\(22\)xr2; 12.4\(22\)xr3; 12.4\(22\)xr4; 12.4\(22\)xr5; 12.4\(22\)xr6; 12.4\(22\)xr7; 12.4\(22\)xr8; 12.4\(22\)xr9; 12.4\(22\)xr10; 12.4\(22\)xr11; 12.4\(22\)xr12; 12.4\(24\)md; 12.4\(24\)md1; 12.4\(24\)md2; 12.4\(24\)md3; 12.4\(24\)md4; 12.4\(24\)md5; 12.4\(24\)md6; 12.4\(24\)md7; 12.4\(24\)mda1; 12.4\(24\)mda2; 12.4\(24\)mda3; 12.4\(24\)mda4; 12.4\(24\)mda5; 12.4\(24\)mda6; 12.4\(24\)mda7; 12.4\(24\)mda8; 12.4\(24\)mda9; 12.4\(24\)mda10; 12.4\(24\)mda11; 12.4\(24\)mda12; 12.4\(24\)mda13; 12.4\(24\)mdb; 12.4\(24\)mdb1; 12.4\(24\)mdb3; 12.4\(24\)mdb4; 12.4\(24\)mdb5; 12.4\(24\)mdb5a; 12.4\(24\)mdb6; 12.4\(24\)mdb7; 12.4\(24\)mdb8; 12.4\(24\)mdb9; 12.4\(24\)mdb10; 12.4\(24\)mdb11; 12.4\(24\)mdb12; 12.4\(24\)mdb13; 12.4\(24\)mdb14; 12.4\(24\)mdb15; 12.4\(24\)mdb16; 12.4\(24\)mdb17; 12.4\(24\)mdb18; 12.4\(24\)mdb19; 12.4\(24\)t; 12.4\(24\)t1; 12.4\(24\)t2; 12.4\(24\)t3; 12.4\(24\)t3e; 12.4\(24\)t3f; 12.4\(24\)t4; 12.4\(24\)t4a; 12.4\(24\)t4b; 12.4\(24\)t4c; 12.4\(24\)t4d; 12.4\(24\)t4e; 12.4\(24\)t4f; 12.4\(24\)t4l; 12.4\(24\)t5; 12.4\(24\)t6; 12.4\(24\)t7; 12.4\(24\)t8; 12.4\(24\)yg; 12.4\(24\)yg1; 12.4\(24\)yg2; 12.4\(24\)yg3; 12.4\(24\)yg4; 15.0\(1\)m; 15.0\(1\)m1; 15.0\(1\)m2; 15.0\(1\)m3; 15.0\(1\)m4; 15.0\(1\)m5; 15.0\(1\)m6; 15.0\(1\)m7; 15.0\(1\)m8; 15.0\(1\)m9; 15.0\(1\)m10; 15.0\(1\)mr; 15.0\(1\)s; 15.0\(1\)s1; 15.0\(1\)s2; 15.0\(1\)s3a; 15.0\(1\)s4; 15.0\(1\)s4a; 15.0\(1\)s5; 15.0\(1\)s6; 15.0\(1\)xa; 15.0\(1\)xa1; 15.0\(1\)xa2; 15.0\(1\)xa3; 15.0\(1\)xa4; 15.0\(1\)xa5; 15.0\(2\)ea; 15.0\(2\)ea1; 15.0\(2\)ej; 15.0\(2\)ej1; 15.0\(2\)ek; 15.0\(2\)ek1; 15.0\(2\)ex; 15.0\(2\)ex1; 15.0\(2\)ex2; 15.0\(2\)ex3; 15.0\(2\)ex4; 15.0\(2\)ex5; 15.0\(2\)ex8; 15.0\(2\)ex10; 15.0\(2\)ex11; 15.0\(2\)ex12; 15.0\(2\)ex13; 15.0\(2\)ey; 15.0\(2\)ey1; 15.0\(2\)ey2; 15.0\(2\)ey3; 15.0\(2\)ez; 15.0\(2\)mr; 15.0\(2\)se; 15.0\(2\)se1; 15.0\(2\)se2; 15.0\(2\)se3; 15.0\(2\)se4; 15.0\(2\)se5; 15.0\(2\)se6; 15.0\(2\)se7; 15.0\(2\)se8; 15.0\(2\)se9; 15.0\(2\)se10; 15.0\(2\)se10a; 15.0\(2\)se11; 15.0\(2\)se12; 15.0\(2\)se13; 15.0\(2a\)ex5; 15.1\(1\)s; 15.1\(1\)s1; 15.1\(1\)s2; 15.1\(1\)sg; 15.1\(1\)sg1; 15.1\(1\)sg2; 15.1\(1\)sy; 15.1\(1\)sy1; 15.1\(1\)sy2; 15.1\(1\)sy3; 15.1\(1\)sy4; 15.1\(1\)sy5; 15.1\(1\)sy6; 15.1\(1\)t; 15.1\(1\)t1; 15.1\(1\)t2; 15.1\(1\)t3; 15.1\(1\)t4; 15.1\(1\)t5; 15.1\(1\)xb; 15.1\(2\)gc; 15.1\(2\)gc1; 15.1\(2\)gc2; 15.1\(2\)s; 15.1\(2\)s1; 15.1\(2\)s2; 15.1\(2\)sg; 15.1\(2\)sg1; 15.1\(2\)sg2; 15.1\(2\)sg3; 15.1\(2\)sg4; 15.1\(2\)sg5; 15.1\(2\)sg6; 15.1\(2\)sg7; 15.1\(2\)sg8; 15.1\(2\)sy; 15.1\(2\)sy1; 15.1\(2\)sy2; 15.1\(2\)sy3; 15.1\(2\)sy4; 15.1\(2\)sy4a; 15.1\(2\)sy5; 15.1\(2\)sy6; 15.1\(2\)sy7; 15.1\(2\)sy8; 15.1\(2\)sy9; 15.1\(2\)sy10; 15.1\(2\)sy11; 15.1\(2\)sy12; 15.1\(2\)sy13; 15.1\(2\)sy14; 15.1\(2\)sy15; 15.1\(2\)sy16; 15.1\(2\)t; 15.1\(2\)t0a; 15.1\(2\)t1; 15.1\(2\)t2; 15.1\(2\)t2a; 15.1\(2\)t3; 15.1\(2\)t4; 15.1\(2\)t5; 15.1\(3\)mra; 15.1\(3\)mra1; 15.1\(3\)mra2; 15.1\(3\)mra3; 15.1\(3\)mra4; 15.1\(3\)s; 15.1\(3\)s0a; 15.1\(3\)s1; 15.1\(3\)s2; 15.1\(3\)s3; 15.1\(3\)s4; 15.1\(3\)s5; 15.1\(3\)s5a; 15.1\(3\)s6; 15.1\(3\)svb1; 15.1\(3\)svb2; 15.1\(3\)svd; 15.1\(3\)svd1; 15.1\(3\)svd2; 15.1\(3\)sve; 15.1\(3\)svf; 15.1\(3\)svf1; 15.1\(3\)svg; 15.1\(3\)svj2; 15.1\(3\)t; 15.1\(3\)t1; 15.1\(3\)t2; 15.1\(3\)t3; 15.1\(3\)t4; 15.1\(4\)gc; 15.1\(4\)gc1; 15.1\(4\)gc2; 15.1\(4\)m; 15.1\(4\)m1; 15.1\(4\)m2; 15.1\(4\)m3; 15.1\(4\)m3a; 15.1\(4\)m4; 15.1\(4\)m5; 15.1\(4\)m6; 15.1\(4\)m7; 15.1\(4\)m8; 15.1\(4\)m9; 15.1\(4\)m10; 15.2\(1\)e; 15.2\(1\)e1; 15.2\(1\)e2; 15.2\(1\)e3; 15.2\(1\)ey; 15.2\(1\)gc; 15.2\(1\)gc1; 15.2\(1\)gc2; 15.2\(1\)s; 15.2\(1\)s1; 15.2\(1\)s2; 15.2\(1\)sy; 15.2\(1\)sy0a; 15.2\(1\)sy1; 15.2\(1\)sy1a; 15.2\(1\)sy2; 15.2\(1\)sy3; 15.2\(1\)sy4; 15.2\(1\)sy5; 15.2\(1\)sy6; 15.2\(1\)sy7; 15.2\(1\)sy8; 15.2\(2\)e; 15.2\(2\)e1; 15.2\(2\)e2; 15.2\(2\)e3; 15.2\(2\)e4; 15.2\(2\)e5; 15.2\(2\)e5a; 15.2\(2\)e5b; 15.2\(2\)e6; 15.2\(2\)e7; 15.2\(2\)e7b; 15.2\(2\)e8; 15.2\(2\)e9; 15.2\(2\)e10; 15.2\(2\)ea; 15.2\(2\)ea1; 15.2\(2\)ea2; 15.2\(2\)ea3; 15.2\(2\)eb; 15.2\(2\)eb1; 15.2\(2\)eb2; 15.2\(2\)gc; 15.2\(2\)s; 15.2\(2\)s0a; 15.2\(2\)s0c; 15.2\(2\)s1; 15.2\(2\)s2; 15.2\(2\)sy; 15.2\(2\)sy1; 15.2\(2\)sy2; 15.2\(2\)sy3; 15.2\(2a\)e1; 15.2\(2a\)e2; 15.2\(3\)e; 15.2\(3\)e1; 15.2\(3\)e2; 15.2\(3\)e3; 15.2\(3\)e4; 15.2\(3\)e5; 15.2\(3\)ea; 15.2\(3\)gc; 15.2\(3\)gc1; 15.2\(3a\)e; 15.2\(4\)e; 15.2\(4\)e1; 15.2\(4\)e2; 15.2\(4\)e3; 15.2\(4\)e4; 15.2\(4\)e5; 15.2\(4\)e5a; 15.2\(4\)e6; 15.2\(4\)e7; 15.2\(4\)e8; 15.2\(4\)e9; 15.2\(4\)e10; 15.2\(4\)e10a; 15.2\(4\)e10d; 15.2\(4\)ea; 15.2\(4\)ea1; 15.2\(4\)ea3; 15.2\(4\)ea4; 15.2\(4\)ea5; 15.2\(4\)ea6; 15.2\(4\)ea7; 15.2\(4\)ea8; 15.2\(4\)ea9; 15.2\(4\)ea9a; 15.2\(4\)ec1; 15.2\(4\)ec2; 15.2\(4\)gc; 15.2\(4\)gc1; 15.2\(4\)gc2; 15.2\(4\)gc3; 15.2\(4\)m; 15.2\(4\)m1; 15.2\(4\)m2; 15.2\(4\)m3; 15.2\(4\)m4; 15.2\(4\)m5; 15.2\(4\)m6; 15.2\(4\)m6a; 15.2\(4\)m7; 15.2\(4\)m8; 15.2\(4\)m9; 15.2\(4\)m10; 15.2\(4\)m11; 15.2\(4\)s; 15.2\(4\)s1; 15.2\(4\)s2; 15.2\(4\)s3; 15.2\(4\)s3a; 15.2\(4\)s4; 15.2\(4\)s4a; 15.2\(4\)s5; 15.2\(4\)s6; 15.2\(4\)s7; 15.2\(5\)e; 15.2\(5\)e1; 15.2\(5\)e2; 15.2\(5\)e2b; 15.2\(5\)e2c; 15.2\(5\)ea; 15.2\(5\)ex; 15.2\(5a\)e; 15.2\(5a\)e1; 15.2\(5b\)e; 15.2\(5c\)e; 15.2\(6\)e; 15.2\(6\)e0a; 15.2\(6\)e0c; 15.2\(6\)e1; 15.2\(6\)e2; 15.2\(6\)e2a; 15.2\(6\)e2b; 15.2\(6\)e3; 15.2\(6\)eb; 15.2\(7\)e; 15.2\(7\)e0a; 15.2\(7\)e0b; 15.2\(7\)e0s; 15.2\(7\)e1; 15.2\(7\)e1a; 15.2\(7\)e2; 15.2\(7\)e2a; 15.2\(7\)e3; 15.2\(7\)e3k; 15.2\(7\)e4; 15.2\(7\)e5; 15.2\(7\)e6; 15.2\(7\)e7; 15.2\(7\)e8; 15.2\(7a\)e0b; 15.2\(7b\)e0b; 15.2\(8\)e; 15.2\(8\)e1; 15.2\(8\)e2; 15.2\(8\)e3; 15.2\(8\)e4; 15.3\(1\)s; 15.3\(1\)s1; 15.3\(1\)s2; 15.3\(1\)sy; 15.3\(1\)sy1; 15.3\(1\)sy2; 15.3\(1\)t; 15.3\(1\)t1; 15.3\(1\)t2; 15.3\(1\)t3; 15.3\(1\)t4; 15.3\(2\)s; 15.3\(2\)s1; 15.3\(2\)s2; 15.3\(2\)t; 15.3\(2\)t1; 15.3\(2\)t2; 15.3\(2\)t3; 15.3\(2\)t4; 15.3\(3\)m; 15.3\(3\)m1; 15.3\(3\)m2; 15.3\(3\)m3; 15.3\(3\)m4; 15.3\(3\)m5; 15.3\(3\)m6; 15.3\(3\)m7; 15.3\(3\)m8; 15.3\(3\)m8a; 15.3\(3\)m9; 15.3\(3\)m10; 15.3\(3\)s; 15.3\(3\)s1; 15.3\(3\)s1a; 15.3\(3\)s2; 15.3\(3\)s3; 15.3\(3\)s4; 15.3\(3\)s5; 15.3\(3\)s6; 15.3\(3\)s7; 15.3\(3\)s8; 15.3\(3\)s8a; 15.3\(3\)s9; 15.3\(3\)s10; 15.4\(1\)cg; 15.4\(1\)cg1; 15.4\(1\)s; 15.4\(1\)s1; 15.4\(1\)s2; 15.4\(1\)s3; 15.4\(1\)s4; 15.4\(1\)sy; 15.4\(1\)sy1; 15.4\(1\)sy2; 15.4\(1\)sy3; 15.4\(1\)sy4; 15.4\(1\)t; 15.4\(1\)t1; 15.4\(1\)t2; 15.4\(1\)t3; 15.4\(1\)t4; 15.4\(2\)cg; 15.4\(2\)s; 15.4\(2\)s1; 15.4\(2\)s2; 15.4\(2\)s3; 15.4\(2\)s4; 15.4\(2\)t; 15.4\(2\)t1; 15.4\(2\)t2; 15.4\(2\)t3; 15.4\(2\)t4; 15.4\(3\)m; 15.4\(3\)m1; 15.4\(3\)m2; 15.4\(3\)m3; 15.4\(3\)m4; 15.4\(3\)m5; 15.4\(3\)m6; 15.4\(3\)m6a; 15.4\(3\)m7; 15.4\(3\)m8; 15.4\(3\)m9; 15.4\(3\)m10; 15.4\(3\)s; 15.4\(3\)s1; 15.4\(3\)s2; 15.4\(3\)s3; 15.4\(3\)s4; 15.4\(3\)s5; 15.4\(3\)s6; 15.4\(3\)s6a; 15.4\(3\)s7; 15.4\(3\)s8; 15.4\(3\)s9; 15.4\(3\)s10; 15.5\(1\)s; 15.5\(1\)s1; 15.5\(1\)s2; 15.5\(1\)s3; 15.5\(1\)s4; 15.5\(1\)sy; 15.5\(1\)sy1; 15.5\(1\)sy2; 15.5\(1\)sy3; 15.5\(1\)sy4; 15.5\(1\)sy5; 15.5\(1\)sy6; 15.5\(1\)sy7; 15.5\(1\)sy8; 15.5\(1\)sy9; 15.5\(1\)sy10; 15.5\(1\)sy11; 15.5\(1\)t; 15.5\(1\)t1; 15.5\(1\)t2; 15.5\(1\)t3; 15.5\(1\)t4; 15.5\(2\)s; 15.5\(2\)s1; 15.5\(2\)s2; 15.5\(2\)s3; 15.5\(2\)s4; 15.5\(2\)t; 15.5\(2\)t1; 15.5\(2\)t2; 15.5\(2\)t3; 15.5\(2\)t4; 15.5\(3\)m; 15.5\(3\)m0a; 15.5\(3\)m1; 15.5\(3\)m2; 15.5\(3\)m3; 15.5\(3\)m4; 15.5\(3\)m4a; 15.5\(3\)m5; 15.5\(3\)m6; 15.5\(3\)m6a; 15.5\(3\)m7; 15.5\(3\)m8; 15.5\(3\)m9; 15.5\(3\)m10; 15.5\(3\)s; 15.5\(3\)s0a; 15.5\(3\)s1; 15.5\(3\)s1a; 15.5\(3\)s2; 15.5\(3\)s3; 15.5\(3\)s4; 15.5\(3\)s5; 15.5\(3\)s6; 15.5\(3\)s6a; 15.5\(3\)s6b; 15.5\(3\)s7; 15.5\(3\)s8; 15.5\(3\)s9; 15.5\(3\)s9a; 15.5\(3\)s10; 15.5\(3\)sn; 15.6\(1\)s; 15.6\(1\)s1; 15.6\(1\)s2; 15.6\(1\)s3; 15.6\(1\)s4; 15.6\(1\)t; 15.6\(1\)t0a; 15.6\(1\)t1; 15.6\(1\)t2; 15.6\(1\)t3; 15.6\(2\)s; 15.6\(2\)s1; 15.6\(2\)s2; 15.6\(2\)s3; 15.6\(2\)s4; 15.6\(2\)sn; 15.6\(2\)sp; 15.6\(2\)sp1; 15.6\(2\)sp2; 15.6\(2\)sp3; 15.6\(2\)sp4; 15.6\(2\)sp5; 15.6\(2\)sp6; 15.6\(2\)sp7; 15.6\(2\)sp8; 15.6\(2\)sp9; 15.6\(2\)sp10; 15.6\(2\)t; 15.6\(2\)t1; 15.6\(2\)t2; 15.6\(2\)t3; 15.6\(3\)m; 15.6\(3\)m0a; 15.6\(3\)m1; 15.6\(3\)m1b; 15.6\(3\)m2; 15.6\(3\)m2a; 15.6\(3\)m3; 15.6\(3\)m3a; 15.6\(3\)m4; 15.6\(3\)m5; 15.6\(3\)m6; 15.6\(3\)m6a; 15.6\(3\)m6b; 15.6\(3\)m7; 15.6\(3\)m8; 15.6\(3\)m9; 15.7\(3\)m; 15.7\(3\)m0a; 15.7\(3\)m1; 15.7\(3\)m2; 15.7\(3\)m3; 15.7\(3\)m4; 15.7\(3\)m4a; 15.7\(3\)m4b; 15.7\(3\)m5; 15.7\(3\)m6; 15.7\(3\)m7; 15.7\(3\)m8; 15.7\(3\)m9; 15.8\(3\)m; 15.8\(3\)m0a; 15.8\(3\)m0b; 15.8\(3\)m1; 15.8\(3\)m1a; 15.8\(3\)m2; 15.8\(3\)m2a; 15.8\(3\)m3; 15.8\(3\)m3a; 15.8\(3\)m3b; 15.8\(3\)m4; 15.8\(3\)m5; 15.8\(3\)m6; 15.8\(3\)m7; 15.8\(3\)m8; 15.8\(3\)m9; 15.8\(3\)m10; 15.9\(3\)m; 15.9\(3\)m0a; 15.9\(3\)m1; 15.9\(3\)m2; 15.9\(3\)m2a; 15.9\(3\)m3; 15.9\(3\)m3a; 15.9\(3\)m3b; 15.9\(3\)m4; 15.9\(3\)m4a; 15.9\(3\)m5; 15.9\(3\)m6; 15.9\(3\)m6a; 15.9\(3\)m6b; 15.9\(3\)m7; 15.9\(3\)m7a |
| cisco | ios xe | 3.3.0sg; 3.3.1sg; 3.3.2sg; 3.4.0sg; 3.4.1sg; 3.4.2sg; 3.4.3sg; 3.4.4sg; 3.4.5sg; 3.4.6sg; 3.4.7sg; 3.4.8sg; 3.5.0e; 3.5.1e; 3.5.2e; 3.5.3e; 3.6.0e; 3.6.1e; 3.6.2ae; 3.6.2e; 3.6.3e; 3.6.4e; 3.6.5ae; 3.6.5be; 3.6.5e; 3.6.6e; 3.6.7be; 3.6.7e; 3.6.8e; 3.6.9e; 3.6.10e; 3.7.0bs; 3.7.0s; 3.7.1as; 3.7.1s; 3.7.2s; 3.7.2ts; 3.7.3s; 3.7.4as; 3.7.4s; 3.7.5s; 3.7.6s; 3.7.7s; 3.8.0e; 3.8.0s; 3.8.1e; 3.8.1s; 3.8.2e; 3.8.2s; 3.8.3e; 3.8.4e; 3.8.5ae; 3.8.5e; 3.8.6e; 3.8.7e; 3.8.8e; 3.8.9e; 3.8.10e; 3.9.0as; 3.9.0e; 3.9.0s; 3.9.1as; 3.9.1e; 3.9.1s; 3.9.2e; 3.9.2s; 3.10.0ce; 3.10.0e; 3.10.0s; 3.10.1e; 3.10.1s; 3.10.1xbs; 3.10.2e; 3.10.2s; 3.10.2ts; 3.10.3e; 3.10.3s; 3.10.4s; 3.10.5s; 3.10.6s; 3.10.7s; 3.10.8as; 3.10.8s; 3.10.9s; 3.10.10s; 3.11.0e; 3.11.0s; 3.11.1ae; 3.11.1e; 3.11.1s; 3.11.2e; 3.11.2s; 3.11.3ae; 3.11.3e; 3.11.3s; 3.11.4e; 3.11.4s; 3.11.5e; 3.11.6e; 3.11.7e; 3.11.8e; 3.12.0as; 3.12.0s; 3.12.1s; 3.12.2s; 3.12.3s; 3.12.4s; 3.13.0as; 3.13.0s; 3.13.1s; 3.13.2as; 3.13.2s; 3.13.3s; 3.13.4s; 3.13.5as; 3.13.5s; 3.13.6as; 3.13.6s; 3.13.7as; 3.13.7s; 3.13.8s; 3.13.9s; 3.13.10s; 3.14.0s; 3.14.1s; 3.14.2s; 3.14.3s; 3.14.4s; 3.15.0s; 3.15.1cs; 3.15.1s; 3.15.2s; 3.15.3s; 3.15.4s; 3.16.0cs; 3.16.0s; 3.16.1as; 3.16.1s; 3.16.2as; 3.16.2bs; 3.16.2s; 3.16.3as; 3.16.3s; 3.16.4as; 3.16.4bs; 3.16.4ds; 3.16.4s; 3.16.5s; 3.16.6bs; 3.16.6s; 3.16.7as; 3.16.7bs; 3.16.7s; 3.16.8s; 3.16.9s; 3.16.10s; 3.17.0s; 3.17.1as; 3.17.1s; 3.17.2s; 3.17.3s; 3.17.4s; 3.18.0as; 3.18.0s; 3.18.0sp; 3.18.1asp; 3.18.1bsp; 3.18.1csp; 3.18.1s; 3.18.1sp; 3.18.2asp; 3.18.2s; 3.18.2sp; 3.18.3asp; 3.18.3bsp; 3.18.3s; 3.18.3sp; 3.18.4s; 3.18.4sp; 3.18.5sp; 3.18.6sp; 3.18.7sp; 3.18.8asp; 3.18.9sp; 16.1.1; 16.1.2; 16.1.3; 16.2.1; 16.2.2; 16.3.1; 16.3.1a; 16.3.2; 16.3.3; 16.3.4; 16.3.5; 16.3.5b; 16.3.6; 16.3.7; 16.3.8; 16.3.9; 16.3.10; 16.3.11; 16.4.1; 16.4.2; 16.4.3; 16.5.1; 16.5.1a; 16.5.1b; 16.5.2; 16.5.3; 16.6.1; 16.6.2; 16.6.3; 16.6.4; 16.6.4a; 16.6.5; 16.6.5a; 16.6.6; 16.6.7; 16.6.8; 16.6.9; 16.6.10; 16.7.1; 16.7.1a; 16.7.1b; 16.7.2; 16.7.3; 16.7.4; 16.8.1; 16.8.1a; 16.8.1b; 16.8.1c; 16.8.1d; 16.8.1e; 16.8.1s; 16.8.2; 16.8.3; 16.9.1; 16.9.1a; 16.9.1b; 16.9.1s; 16.9.2; 16.9.3; 16.9.3a; 16.9.4; 16.9.5; 16.9.5f; 16.9.6; 16.9.7; 16.9.8; 16.10.1; 16.10.1a; 16.10.1b; 16.10.1c; 16.10.1d; 16.10.1e; 16.10.1f; 16.10.1g; 16.10.1s; 16.10.2; 16.10.3; 16.11.1; 16.11.1a; 16.11.1b; 16.11.1s; 16.11.2; 16.12.1; 16.12.1a; 16.12.1c; 16.12.1s; 16.12.1t; 16.12.1w; 16.12.1x; 16.12.1y; 16.12.1z1; 16.12.1z2; 16.12.2; 16.12.2a; 16.12.2s; 16.12.3; 16.12.3a; 16.12.3s; 16.12.4; 16.12.4a; 16.12.5; 16.12.5a; 16.12.5b; 16.12.6; 16.12.6a; 16.12.7; 16.12.8; 16.12.9; 17.1.1; 17.1.1a; 17.1.1s; 17.1.1t; 17.1.3; 17.2.1; 17.2.1a; 17.2.1r; 17.2.1v; 17.2.2; 17.2.3; 17.3.1; 17.3.1a; 17.3.1w; 17.3.1x; 17.3.1z; 17.3.2; 17.3.2a; 17.3.3; 17.3.4; 17.3.4a; 17.3.4b; 17.3.4c; 17.3.5; 17.3.5a; 17.3.5b; 17.3.6; 17.3.7; 17.4.1; 17.4.1a; 17.4.1b; 17.4.2; 17.4.2a; 17.5.1; 17.5.1a; 17.5.1c; 17.6.1; 17.6.1a; 17.6.1w; 17.6.1x; 17.6.1y; 17.6.1z; 17.6.1z1; 17.6.2; 17.6.3; 17.6.3a; 17.6.4; 17.6.5; 17.6.5a; 17.7.1; 17.7.1a; 17.7.1b; 17.7.2; 17.8.1; 17.8.1a; 17.9.1; 17.9.1a; 17.9.1w; 17.9.1x; 17.9.1x1; 17.9.1y; 17.9.1y1; 17.9.2; 17.9.2a; 17.9.3; 17.9.3a; 17.10.1; 17.10.1a; 17.10.1b; 17.11.1; 17.11.1a; 17.11.99sw |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
References
Weakness Type
CWE-787: Out-of-bounds Write
An out-of-bounds write vulnerability occurs when a program writes data past the boundaries of an allocated memory buffer, potentially corrupting adjacent memory, crashing the application, or enabling arbitrary code execution. In CVE-2023-20109, the Cisco IOS and IOS XE GET VPN feature fails to properly validate attributes within GDOI and G-IKEv2 protocol messages, allowing a compromised key server or modified group member to trigger an out-of-bounds write condition.
Learn more: CWE-787 — Out-of-bounds Write
Impact Analysis
CVE-2023-20109 carries a CVSS score of 6.6 (Medium), reflecting a notable but constrained threat. The vulnerability is remotely exploitable without physical access, but attack complexity is high, meaning specific conditions must be met for successful exploitation — the attacker must already have administrative control of either a GET VPN group member or a key server. Privileges Required (High): the attacker needs elevated administrative credentials, significantly limiting the pool of potential attackers. User Interaction (None): no action is required from the device administrator for exploitation to succeed. Confidentiality (High): successful exploitation grants full access to device configurations and network traffic. Integrity (High): arbitrary code execution allows modification of device behavior, routing tables, and VPN configurations. Availability (High): the attacker can crash the affected device, causing a denial of service for all services relying on that network equipment. Despite the EPSS score of 0.58% indicating limited exploitation probability, the inclusion in CISA's KEV catalog confirms that targeted exploitation has occurred.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2023-20109 in the wild and has included it in the Known Exploited Vulnerabilities catalog with a remediation deadline of October 31, 2023. The EPSS score of 0.58% suggests that while exploitation is possible, it is not yet widespread, likely due to the high prerequisite of already possessing administrative access to a GET VPN group member or key server. The ransomware association for this vulnerability is currently listed as unknown. Vendor advisory and mitigation guidance is available from Cisco.
Remediation
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Consult the Cisco Security Advisory for the list of fixed Cisco IOS and IOS XE software versions and upgrade affected devices accordingly.
- Upgrade Cisco IOS and IOS XE Software to patched versions that address the insufficient attribute validation in the GDOI and G-IKEv2 protocols of the GET VPN feature.
- Secure all GET VPN key servers and group members by enforcing strong authentication, restricting administrative access to trusted personnel only, and monitoring for unauthorized configuration changes. Ensure that key server infrastructure is hardened against compromise, as this is the primary attack prerequisite.
- Monitor GET VPN protocol exchanges for anomalous GDOI or G-IKEv2 attribute values that could indicate exploitation attempts. Review device logs for unexpected reloads, crashes, or signs of code execution on devices participating in GET VPN groups.
- Implement network segmentation to isolate GET VPN management plane traffic from untrusted networks. Apply access control lists to restrict which devices can communicate with key servers and limit administrative access to dedicated management interfaces.
Technical Details
CVE-2023-20109 is an out-of-bounds write vulnerability (CWE-787) in the GET VPN feature of Cisco IOS and IOS XE Software, arising from insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols. The CVSS vector (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H) reflects that while the vulnerability is network-accessible, exploitation requires high attack complexity and high privileges — the attacker must already control a key server or have the ability to modify a group member's configuration to point to an attacker-controlled key server. When a group member processes specially crafted protocol messages containing malformed attributes from the compromised key server, the insufficient validation allows data to be written beyond the bounds of an allocated memory buffer. This out-of-bounds write can corrupt critical data structures, enabling arbitrary code execution with full control of the affected device, or causing a device reload that results in denial of service.
Frequently Asked Questions
Is CVE-2023-20109 being actively exploited?
Yes, CVE-2023-20109 is being actively exploited. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog with a remediation deadline of October 31, 2023. However, with an EPSS score of 0.58%, exploitation appears to be targeted rather than widespread, likely due to the high prerequisite of needing administrative access to exploit it.
What products are affected by CVE-2023-20109?
CVE-2023-20109 affects Cisco IOS Software and Cisco IOS XE Software that have the Group Encrypted Transport VPN (GET VPN) feature configured. Specifically, devices operating as GET VPN group members or key servers using GDOI or G-IKEv2 protocols are vulnerable.
How do I fix CVE-2023-20109?
Upgrade Cisco IOS and IOS XE Software to the fixed versions listed in Cisco's security advisory (cisco-sa-getvpn-rce-g8qR68sx). Additionally, secure all GET VPN key servers against unauthorized access, implement network segmentation for management plane traffic, and monitor for anomalous GDOI/G-IKEv2 protocol behavior.
How severe is CVE-2023-20109?
CVE-2023-20109 is rated Medium severity with a CVSS score of 6.6 out of 10.0. While the impact of successful exploitation is high across confidentiality, integrity, and availability, the attack complexity is also high, requiring the attacker to already possess administrative control of a GET VPN component. It ranks in the 68th percentile for exploitation probability (EPSS).
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.