Security
Loading…

CVE-2023-20109

UNKNOWNKnown Exploited
Description

Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.

Timeline
Published:October 10th, 2023 12:00 AM
Last modified:October 10th, 2023 12:00 AM
Added to KEV:October 10th, 2023
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Cisco

Products

IOS and IOS XE
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute