CVE-2023-20109
published 2023-09-27CVE-2023-20109: A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated…
PriorityP278medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-10-31
Exploited in the wild
EPSS
2.34%
81.8th percentile
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash.
This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a denial of service (DoS) condition. For more information, see the Details ["#details"] section of this advisory.
Affected
2077 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2023-20109 affects devices with GDOI or G-IKEv2 protocol enabled under the GET VPN feature — scope detection to IOS/IOS XE devices with these protocols active ↗
- →Exploitation requires the attacker to either compromise an installed key server or redirect a group member's configuration to an attacker-controlled key server — monitor for unexpected changes to GET VPN key server configuration on group members ↗
- ·Meraki products and devices running IOS XR and NX-OS are NOT affected by CVE-2023-20109 — exclude these from scope ↗
- ·Exploitation requires the attacker to already have administrative control of a key server or group member, implying prior environment compromise — all communication between key server and group members is encrypted and authenticated ↗
CVSS provenance
nvdv3.16.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck6.6MEDIUM
cisa6.6MEDIUM
vendor_cisco6.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
cisa·2023-10-10·CVSS 6.6
CVE-2023-20109 [MEDIUM] CWE-787 Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
Vulnerability: Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
Affected: Cisco IOS and IOS XE
Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-getvpn-rce-g8qR68sx; https://nvd.nist.gov/vuln/detail/CVE-2023-20109
Remediation Due Date: 2023-10-31
Cisco
Cisco IOS and IOS XE Software Cisco Group Encrypted Transport VPN Software Out-of-Bounds Write Vulnerability
vendor_cisco·2023-09-27·CVSS 6.6
CVE-2023-20109 [MEDIUM] CWE-787 Cisco IOS and IOS XE Software Cisco Group Encrypted Transport VPN Software Out-of-Bounds Write Vulnerability
Cisco IOS and IOS XE Software Cisco Group Encrypted Transport VPN Software Out-of-Bounds Write Vulnerability
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash.
This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A succes
Cisco
Cisco IOS and IOS XE Software Cisco Group Encrypted Transport VPN Software Out-of-Bounds Write Vulnerability
vendor_cisco·CVSS 3.1
CVE-2023-20109 Cisco IOS and IOS XE Software Cisco Group Encrypted Transport VPN Software Out-of-Bounds Write Vulnerability
CVE-2023-20109: Cisco IOS and IOS XE Software Cisco Group Encrypted Transport VPN Software Out-of-Bounds Write Vulnerability
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the atta
GHSA
GHSA-7h8h-8482-vvfh: A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authentica
ghsa_unreviewed·2023-09-27
CVE-2023-20109 [MEDIUM] CWE-787 GHSA-7h8h-8482-vvfh: A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authentica
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash.
This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system o
VulnCheck
Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
vulncheck·2023·CVSS 6.6
CVE-2023-20109 [MEDIUM] CWE-787 Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability
Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.
Affected: Cisco IOS and IOS XE Software
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-getvpn-rce-g8qR68sx; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://isc.sans.edu/diary/rss
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Cisco discloses new IOS XE zero-day exploited to deploy malware implant
blogs_bleepingcomputer·2023-10-20·CVSS 7.2
CVE-2023-20273 [HIGH] Cisco discloses new IOS XE zero-day exploited to deploy malware implant
## Cisco discloses new IOS XE zero-day exploited to deploy malware implant
## Sergiu Gatlan
Cisco disclosed a new high-severity zero-day (CVE-2023-20273) today, actively exploited to deploy malicious implants on IOS XE devices compromised using the CVE-2023-20198 zero-day unveiled earlier this week.
The company said it found a fix for both vulnerabilities and estimates it will be released to customers via the Cisco Software Download Center over the weekend, starting October 22.
"Fixes for both CVE-2023-20198 and CVE-2023-20273 are estimated to be available on October 22. The CVE-2021-1435 that had previously been mentioned is no longer assessed to be associated with this activity," Cisco said today.
On Monday, Cisco disclosed that unauthenticated attackers have been exploiting the CVE
Bleepingcomputer
Over 10,000 Cisco devices hacked in IOS XE zero-day attacks
blogs_bleepingcomputer·2023-10-17·CVSS 10.0
CVE-2023-20198 [CRITICAL] Over 10,000 Cisco devices hacked in IOS XE zero-day attacks
## Over 10,000 Cisco devices hacked in IOS XE zero-day attacks
## Sergiu Gatlan
Update October 17, 16:40 EDT: Added new information on breached Cisco IOS XE devices.
Update October 18, 05:06 EDT: Orange Cyberdefense CERT discovered over 34.5K Cisco IOS XE devices compromised in CVE-2023-20198 attacks.
Attackers have exploited a recently disclosed critical zero-day bug to compromise and infect over 10,000 Cisco IOS XE devices with malicious implants.
The list of products running Cisco IOS XE software includes enterprise switches, aggregation and industrial routers, access points, wireless controllers, and more.
According to threat intelligence company VulnCheck, the maximum severity vulnerability (CVE-2023-20198) has been extensively exploited in attacks targeting Cisco IOS XE systems
Tenable
CVE-2023-20198: Zero-Day Vulnerability in Cisco IOS XE Exploited in the Wild
blogs_tenable·2023-10-16·CVSS 10.0
[CRITICAL] CVE-2023-20198: Zero-Day Vulnerability in Cisco IOS XE Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Cisco warns of new IOS XE zero-day actively exploited in attacks
blogs_bleepingcomputer·2023-10-16·CVSS 7.2
CVE-2023-20198 [HIGH] Cisco warns of new IOS XE zero-day actively exploited in attacks
## Cisco warns of new IOS XE zero-day actively exploited in attacks
## Sergiu Gatlan
Cisco warned admins today of a new maximum severity authentication bypass zero-day in its IOS XE software that lets unauthenticated attackers gain full administrator privileges and take complete control of affected routers and switches remotely.
The company says the critical vulnerability (tracked as CVE-2023-20198 and still waiting for a patch) only affects devices with the Web User Interface (Web UI) feature enabled, which also have the HTTP or HTTPS Server feature toggled on.
"Cisco has identified active exploitation of a previously unknown vulnerability in the Web User Interface (Web UI) feature of Cisco IOS XE software (CVE-2023-20198) when exposed to the internet or untrusted networks," the compa
Bleepingcomputer
Cisco fixes hard-coded root credentials in Emergency Responder
blogs_bleepingcomputer·2023-10-04·CVSS 9.8
CVE-2023-20101 [CRITICAL] Cisco fixes hard-coded root credentials in Emergency Responder
## Cisco fixes hard-coded root credentials in Emergency Responder
## Sergiu Gatlan
Cisco released security updates to fix a Cisco Emergency Responder (CER) vulnerability that let attackers log into unpatched systems using hard-coded credentials.
CER helps organizations respond effectively to emergencies by enabling accurate location tracking of IP phones, allowing emergency calls to be routed to the appropriate Public Safety Answering Point (PSAP).
Tracked as CVE-2023-20101, the security flaw allows unauthenticated attackers to access a targeted device using the root account, which had default, static credentials that could not be modified or removed.
"This vulnerability is due to the presence of static user credentials for the root account that are typically reserved for use during d
Bleepingcomputer
Cisco urges admins to fix IOS software zero-day exploited in attacks
blogs_bleepingcomputer·2023-09-28·CVSS 6.6
CVE-2023-20109 [MEDIUM] Cisco urges admins to fix IOS software zero-day exploited in attacks
## Cisco urges admins to fix IOS software zero-day exploited in attacks
## Sergiu Gatlan
Cisco warned customers on Wednesday to patch a zero-day IOS and IOS XE software vulnerability targeted by attackers in the wild.
Discovered by X. B. of the Cisco Advanced Security Initiatives Group (ASIG), this medium-severity security flaw ( CVE-2023-20109 ) stems from inadequate attribute validation within the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature.
Luckily, successful exploitation requirements demand that potential attackers have admin control of either a key server or a group member. This implies that the attackers have already infiltrated the environment, seeing that all communication between the key server and group members is encrypted and authenti
2023-09-27
Published
2023-10-10
Added to CISA KEV
Exploited in the wild