Tuesday, May 6, 2025
HomeCiscoCisco IOS Software Zero-day Exploited in Attacks

Cisco IOS Software Zero-day Exploited in Attacks

Published on

SIEM as a Service

Follow Us on Google News

Cisco has issued fixes to address a vulnerability in the GET VPN feature of IOS and IOS XE software that has been exploited in attacks.

A remote attacker who has administrative access to a group member or a key server can exploit this vulnerability to run arbitrary code or bring down an affected device.

Cisco GET VPN is a set of features required for secure IP multicast group communication or unicast traffic over a private WAN that originates or flows through a Cisco IOS device. 

- Advertisement - Google News

GET VPN integrates the group key management protocol with IPsec encryption to offer users an efficient way to secure IP multicast or unicast communication.

Document
FREE Demo

Deploy Advanced AI-Powered Email Security Solution

Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware

Details of the Vulnerability

With a CVSS base score of 6.6, the Out-of-Bounds Write Vulnerability reported by Cisco is tracked as CVE-2023-20109 and has a ‘medium’ severity range.

“This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature”, Cisco said in its advisory.

A hacker could take advantage of this vulnerability by compromising an installed key server or changing a group member’s settings to point to a key server under the attacker’s control.

If the exploit is successful, the attacker may be able to run arbitrary code and take complete control of the target system, or they may force the target system to reload and create a DoS.

Affected Products

If a Cisco product had the GDOI or G-IKEv2 protocol enabled and was running a vulnerable version of the Cisco IOS software or Cisco IOS XE software, it is considered vulnerable.

Products Not Vulnerable

  •     IOS XR Software
  •     Meraki products
  •     NX-OS Software

This vulnerability, according to Cisco, can only be exploited in one of two ways:

  • The attacker compromises the existing key server and gains access to the GDOI or G-IKEv2 packets sent by the key server to the group member.
  • The attacker creates and installs their own key server and then reconfigures the group member to interact with the attacker-controlled key server.

Mitigation Measures

As stated in the advisory, Cisco recommends that affected users apply software updates as early as possible.

Cisco confirmed that there are no workarounds that address this vulnerability.

Protect yourself from vulnerabilities using Patch Manager Plus to quickly patch over 850 third-party applications. Take advantage of the free trial to ensure 100% security.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Exploit Fake Chrome Error Pages to Deploy Malicious Scripts on Windows Users

Hackers are leveraging a sophisticated social engineering technique dubbed "ClickFix" to trick Windows users...

New ClickFix Attack Imitates Ministry of Defence Website to Target Windows & Linux Systems

A newly identified cyberattack campaign has surfaced, leveraging the recognizable branding of India's Ministry...

Threat Actor Evades SentinelOne EDR to Deploy Babuk Ransomware

Aon’s Stroz Friedberg Incident Response Services has uncovered a method used by a threat...

Samsung MagicINFO 9 Server Vulnerability Actively Exploited in the Wild

A critical security vulnerability in the Samsung MagicINFO 9 Server has come under active...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Exploit Fake Chrome Error Pages to Deploy Malicious Scripts on Windows Users

Hackers are leveraging a sophisticated social engineering technique dubbed "ClickFix" to trick Windows users...

New ClickFix Attack Imitates Ministry of Defence Website to Target Windows & Linux Systems

A newly identified cyberattack campaign has surfaced, leveraging the recognizable branding of India's Ministry...

Threat Actor Evades SentinelOne EDR to Deploy Babuk Ransomware

Aon’s Stroz Friedberg Incident Response Services has uncovered a method used by a threat...