Threat Advisory

Cisco Urges Admins To Fix IOS Software Zero-Day Exploited In Attacks

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Cisco has issued a warning to its customers regarding a zero-day vulnerability in its IOS and IOS XE software, which is currently being actively targeted by attackers. The medium-severity security flaw is known as CVE-2023-20109. Successful exploitation of this vulnerability requires the attacker to have administrative control over either a key server or a group member, suggesting prior infiltration. Attackers can leverage the flaw to execute arbitrary code, potentially gaining full control of the affected system or causing it to reload, resulting in a denial of service (DoS) condition. While the extensive access needed for successful exploitation might seem limiting, Cisco has detected attempts to exploit the GET VPN feature, underscoring its significance. Cisco strongly recommends that affected customers upgrade to a fixed software release to address this vulnerability.[/subscribe_to_unlock_form]

Summary:

Cisco has issued a warning to its customers regarding a zero-day vulnerability in its IOS and IOS XE software, which is currently being actively targeted by attackers. The medium-severity security flaw is known as CVE-2023-20109. Successful exploitation of this vulnerability requires the attacker to have administrative control over either a key server or a group member, suggesting prior infiltration. Attackers can leverage the flaw to execute arbitrary code, potentially gaining full control of the affected system or causing it to reload, resulting in a denial of service (DoS) condition. While the extensive access needed for successful exploitation might seem limiting, Cisco has detected attempts to exploit the GET VPN feature, underscoring its significance. Cisco strongly recommends that affected customers upgrade to a fixed software release to address this vulnerability.[emaillocker id="1283"]

Recommendations:

  • We strongly recommend you update the Cisco IOS XE Version to 3.11.1 and Cisco IOS Version 15.4 (1) S1.

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/cisco-urges-admins-to-fix-ios-software-zero-day-exploited-in-attacks/

[/emaillocker]
crossmenu