#VU81270 Out-of-bounds write in Cisco IOS and Cisco IOS XE - CVE-2023-20109
Published: September 29, 2023
Cisco IOS
Cisco IOS XE
Cisco Systems, Inc
Description
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols within the Cisco Group Encrypted Transport VPN (GET VPN) feature. A remote authenticated user with administrative control of either a group member or a key server can trigger an out-of-bounds write and execute arbitrary code on the target system.
Note, the vulnerability has been exploited in the wild.