LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-20109: Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 10, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 31, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-20109 to its Known Exploited Vulnerabilities catalog on Oct 10, 2023, with a federal patch deadline of Oct 31, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative…

CVE-2023-20109 is an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS and IOS XE. An authenticated remote attacker who already holds administrative control of a group member or key server can abuse it to execute malicious code or crash the device. Network infrastructure that relies on GET VPN for encrypted group communications is therefore at risk of full compromise or denial of service once an attacker has obtained those elevated credentials.

Because the flaw sits in core routing and VPN software, successful exploitation can disrupt traffic, enable further lateral movement, or allow persistent control of the device. Teams should treat any device running the affected feature as high priority until the vendor fix is confirmed and applied.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In the GET VPN feature, certain processing of protocol data can write past the bounds of an allocated buffer. An attacker who already possesses administrative privileges on either a group member or a key server can supply crafted input that triggers this write. The result can be arbitrary code execution with the privileges of the affected process or an immediate device crash (denial of service). Exact packet formats, memory offsets, or trigger conditions are not detailed in the public summary; defenders must consult the Cisco advisory for any additional technical notes.

No unauthenticated remote path is described; the attacker must already control a legitimate administrative session on a participating GET VPN node. That prerequisite limits the initial attack surface but does not reduce the impact once the attacker is inside the administrative trust boundary.

Am I affected? How to find it in your systems

Cisco IOS and IOS XE are the operating systems used on a wide range of Cisco routers, switches, and related network appliances. GET VPN is an optional feature typically enabled on devices that participate in large-scale encrypted group overlays. Inventory every Cisco device running IOS or IOS XE, then determine whether GET VPN is configured (look for GDOI or related key-server/group-member statements in the running configuration).

If GET VPN is not in use, the vulnerability is not reachable; still confirm the software version so that future configuration changes do not re-introduce exposure.

How to remediate

The primary remediation is to install the software update that Cisco has released for this vulnerability. Obtain the correct image for each platform and train from the vendor advisory, then schedule a controlled upgrade window. After the upgrade, verify that GET VPN functionality continues to operate as expected and that the new version string matches the fixed release.

If the advisory lists additional configuration changes or feature-specific work-arounds, apply those as well. Where the product can no longer be supported, CISA guidance is to discontinue use. Beyond the patch, apply standard hardening for this class of flaw: restrict administrative access to GET VPN nodes with strong authentication and network ACLs, keep management planes on isolated networks, and ensure that only necessary devices hold group-member or key-server roles.

If you can't patch immediately

Until the vendor update can be installed, reduce risk with compensating controls:

These steps do not eliminate the vulnerability; they only shrink the window of exposure until the official fix is deployed.

If your data may have been exposed

Vulnerabilities that permit code execution on network devices can lead to broader breaches if an attacker uses the foothold to intercept traffic or pivot deeper into the environment. Ransomware use of this specific CVE is not documented. If you suspect compromise, isolate the affected devices, preserve logs, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS and IOS XE
WeaknessCWE-787
Added to CISA KEVOct 10, 2023
Federal patch deadlineOct 31, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities