boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-20109

Cisco IOS and IOS XE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0248   84.1   YES
AFFECTED
  Product                Versions     Fixed
  IOS                    12.4(24)T –  —
  Cisco IOS XE Software  3.7.0S –     —
TIMELINE
  Oct 27  Reserved by cisco
  Sep 27  Published (CNA: cisco)
  Oct 10  Added to CISA KEV, remediation due 2023-10-31
CWE-787 · CNA: cisco · CVSS v3.1 · 2 references · KEV due October 31, 2023

Description

A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a denial of service (DoS) condition. For more information, see the Details ["#details"] section of this advisory.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
October 27, 2022ReservedReserved by cisco
September 27, 2023PublishedPublished (CNA: cisco)
October 10, 2023KEV ADDEDAdded to CISA KEV, remediation due 2023-10-31

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
CiscoIOS—12.4(24)T—
CiscoCisco IOS XE Software—3.7.0S—

Weaknesses

CWE-787

References (2)

Related

Authoritative record: CVE-2023-20109 at cve.org

Vendors: cisco

Weaknesses: CWE-787

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-20109 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.