VDB
CVE-2023-20109
CVE-2023-20109
PUBLISHED
KEV
Es existiert eine Schwachstelle in Cisco IOS und Cisco IOS XE. Diese ist auf eine unzureichende Validierung von Attributen in den Protokollen Group Domain of Interpretation (GDOI) und G-IKEv2 der GET VPN-Funktion zurückzuführen. Ein Angreifer, der administrative Kontrolle über ein Gruppenmitglied oder einen Schlüsselserver hat kann diese Schwachstelle ausnutzen, um beliebigen Code auszuführen und die vollständige Kontrolle über das betroffene System zu erlangen, oder einen Denial of Service zu verursachen.
EPSS 0.63% · 70.8th percentile
Risk Scores
EPSS Score
0.63%
70.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco IOS | |
| Cisco | Cisco IOS XE |
Exploit Intelligence
- CIRCL seen: CVE-2023-20109 (circl-sighting)
- CIRCL seen: CVE-2023-20109 (circl-sighting)
- CIRCL seen: CVE-2023-20109 (circl-sighting)
- CIRCL exploited: CVE-2023-20109 (circl-sighting)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20109 (circl)
- cisco-sa-getvpn-rce-g8qR68sx (circl)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog (certbund)
- kev.json (github-poc)
- kev.json (github-poc)
- kev.json (github-poc)
…and 7 more exploits
Timeline
- Sep 27, 2023 CVE Published
- Sep 28, 2023 EPSS Score
- Oct 10, 2023 CISA KEV Added
- Oct 10, 2023 PoC Published
- Oct 11, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 1, 2023 EPSS Score
- Jan 2, 2024 EPSS Score
- Mar 5, 2024 EPSS Score
- Apr 6, 2024 EPSS Score
- May 8, 2024 EPSS Score
- Jun 9, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-2510.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2510 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-getvpn-rce-g8qR68sx advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aaascp-Tyj4fEJm advisory