Article Details

Scrape Timestamp (UTC): 2023-09-29 03:08:40.127

Source: https://thehackernews.com/2023/09/cisco-warns-of-vulnerability-in-ios-and.html

Original Article Text

Click to Toggle View

Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts. Cisco is warning of attempted exploitation of a security flaw in its IOS Software and IOS XE Software that could permit an authenticated remote attacker to achieve remote code execution on affected systems. The medium-severity vulnerability is tracked as CVE-2023-20109, and has a CVSS score of 6.6. It impacts all versions of the software that have the GDOI or G-IKEv2 protocol enabled. The company said the shortcoming "could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash." It further noted that the issue is the result of insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature and it could be weaponized by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. The vulnerability is said to have been discovered following an internal investigation and source code audit initiated after an "attempted exploitation of the GET VPN feature." The revelation comes as Cisco detailed a set of five flaws in Catalyst SD-WAN Manager (versions 20.3 to 20.12) that could allow an attacker to access an affected instance or cause a denial of service (DoS) condition on an affected system - Successful exploitation of the bugs could allow the threat actor to gain unauthorized access to the application as an arbitrary user, bypass authorization and roll back controller configurations, access the Elasticsearch database of an affected system, access another tenant managed by the same instance, and cause a crash. Customers are recommended to upgrade to a fixed software release to remediate the vulnerabilities.

Daily Brief Summary

CYBERCRIME // Cisco Alerts Customers About Exploitation Attempts in IOS and IOS XE Software

Cisco issued a warning about an attempted exploitation of a security flaw in its IOS Software and IOS XE Software that could permit a remote attacker to execute code on affected systems.

The medium-severity vulnerability has been tracked as CVE-2023-20109 with a CVSS score of 6.6 and affects all versions of the software with the GDOI or G-IKEv2 protocol enabled.

An attacker could exploit the vulnerability by gaining administrative control of either a group member or a key server, causing the affected device to execute an arbitrary code or crash.

The vulnerability was discovered during an internal investigation and source code audit launched after an attempted exploitation of the GET VPN feature.

Cisco also detailed another set of five flaws in its Catalyst SD-WAN Manager that could allow an attacker to gain unauthorized access or a denial of service condition on affected systems.

Customers are urged to upgrade to a fixed software release to remediate these vulnerabilities.