Cisco has issued fixes to address a vulnerability in the GET VPN feature of IOS and IOS XE software that has been exploited in attacks.
A remote attacker who has administrative access to a group member or a key server can exploit this vulnerability to run arbitrary code or bring down an affected device.
Cisco GET VPN is a set of features required for secure IP multicast group communication or unicast traffic over a private WAN that originates or flows through a Cisco IOS device.
GET VPN integrates the group key management protocol with IPsec encryption to offer users an efficient way to secure IP multicast or unicast communication.
Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware
With a CVSS base score of 6.6, the Out-of-Bounds Write Vulnerability reported by Cisco is tracked as CVE-2023-20109 and has a ‘medium’ severity range.
“This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature”, Cisco said in its advisory.
A hacker could take advantage of this vulnerability by compromising an installed key server or changing a group member’s settings to point to a key server under the attacker’s control.
If the exploit is successful, the attacker may be able to run arbitrary code and take complete control of the target system, or they may force the target system to reload and create a DoS.
If a Cisco product had the GDOI or G-IKEv2 protocol enabled and was running a vulnerable version of the Cisco IOS software or Cisco IOS XE software, it is considered vulnerable.
This vulnerability, according to Cisco, can only be exploited in one of two ways:
As stated in the advisory, Cisco recommends that affected users apply software updates as early as possible.
Cisco confirmed that there are no workarounds that address this vulnerability.
Protect yourself from vulnerabilities using Patch Manager Plus to quickly patch over 850 third-party applications. Take advantage of the free trial to ensure 100% security.
Best DNS Management Tools play a crucial role in efficiently managing domain names and their…
Customers can now easily integrate Sweet’s runtime detection and response platform into their AWS environments…
Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling them…
SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases from…
In late October 2024, a coordinated IP spoofing attack targeted the Tor network, prompting abuse…
The Metasploit Framework, a widely used open-source penetration testing tool maintained by Rapid7, has introduced…