Out-of-bounds write in Cisco IOS and Cisco IOS XE - CVE-2023-20109
Published: September 29, 2023
Vulnerability details
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols within the Cisco Group Encrypted Transport VPN (GET VPN) feature. A remote authenticated user with administrative control of either a group member or a key server can trigger an out-of-bounds write and execute arbitrary code on the target system.
Note, the vulnerability has been exploited in the wild.
Affected software
Cisco IOS XE
How to mitigate CVE-2023-20109
Cisco IOS XE - addressed in versions 16.12.10, 17.3.7, 17.9.1y, 17.9.3, 17.9.4, 17.11.1, 17.12.1