QID 379523
Date Published: 2024-03-28
QID 379523: Cisco Duo Authentication for macOS and Duo Authentication for Windows Logon Offline Credentials Replay Vulnerability (cisco-sa-duo-replay-knuNKd)
CVE-2023-20123: A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected Windows device.
This vulnerability exists because session credentials do not properly expire. An attacker could exploit this vulnerability by replaying previously used multifactor authentication (MFA) codes to bypass MFA protection. A successful exploit could allow the attacker to gain unauthorized access to the affected device.
Affected versions:
Cisco Duo Authentication for Windows Logon and RDP Software Release v4.2.1 and earlier
QID Detection Logic:(Authenticated) - Windows - This QID checks for HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall string to check the vulnerable version of the affected product
A successful exploit could allow the attacker to gain unauthorized access to the affected device. Successful exploitation could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device.
Customers are advised to refer to cisco-sa-duo-replay-knuNKd for more information.
- cisco-sa-duo-replay-knuNKd -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-replay-knuNKd
CVEs related to QID 379523
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-duo-replay-knuNKd |
|