PT-2023-5691 · Cisco · Cisco Ios Xe+1
X. B
·
Published
2023-09-27
·
Updated
2025-09-17
·
CVE-2023-20109
CVSS v2.0
7.1
High
| Vector | AV:N/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS and IOS XE Software (affected versions not specified)
Description
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a denial of service (DoS) condition. Approximately 160,000 devices are exposed, and around 40,000 nodes have been compromised by an unknown threat actor.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability. However, Cisco has released software updates that address this vulnerability. As a temporary workaround, consider disabling the GDOI and G-IKEv2 protocols until a patch is available. Restrict access to the GET VPN feature to minimize the risk of exploitation. Avoid using the affected API endpoints until the issue is resolved. Apply the software updates released by Cisco to fix the vulnerability.
RCE
DoS
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios
Cisco Ios Xe