EXPOSURES › CVE-2023-20109
CVE-2023-20109
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco IOS and IOS XE Group Encrypted Transport VPN out-of-bounds write vulnerability allows remote code execution.
Cisco IOS and IOS XE contain a vulnerability in the Group Encrypted Transport VPN feature that allows an authenticated, remote attacker to execute malicious code or cause a device to crash. This is a high-severity remote code execution vulnerability that can be exploited by attackers who have administrative control of either a group member or a key server. DIB organizations should ensure they are using the latest patches and maintaining strict access controls to mitigate this risk.
Shame score — This is a high-severity remote code execution vulnerability that has been actively exploited in the wild, indicating a significant risk to network infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |