QID 378840
Date Published: 2023-10-24
QID 378840: Cisco Duo Device Health Application for Windows Denial of Service (DoS) Vulnerability
A vulnerability in the CryptoService function of Cisco Duo Device Health Application for Windows could allow an authenticated, local attacker with low privileges to conduct directory traversal attacks and overwrite arbitrary files on an affected system.
Affected Products
below 5.2.0
QID Detection Logic (Authenticated):
This checks for vulnerable version of Cisco Duo Device Health Application using registry information.
In a DoS attack, an attacker with malicious intent prevents users from accessing a service.
Solution
Customers are advised to refer to cisco-sa-esa-sma-wsa-xss-cP9DuEmq for more information.
Vendor References
- cisco-sa-duo-dha-filewrite-xPMBMZAK#vp -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-dha-filewrite-xPMBMZAK#vp
CVEs related to QID 378840
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-duo-dha-filewrite-xPMBMZAK#vp |
|