QID 379534
Date Published: 2024-03-27
QID 379534: Cisco Duo Authentication for Windows Logon and RDP Information Disclosure Vulnerability (cisco-sa-duo-infodisc-rLCEqm6T)
CVE-2023-20123: A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information in clear text on an affected system.
This vulnerability is due to improper storage of an unencrypted registry key in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system. A successful exploit could allow the attacker to view sensitive information in clear text.
Affected versions:
Cisco Duo Authentication for Windows Logon and RDP Software Release following versions are affected:
v4.0.0 up to v4.0.7
v4.1.0 up to v4.1.3
v4.2.0 up to v4.2.2
QID Detection Logic:(Authenticated) - Windows - This QID checks for HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall string to check the vulnerable version of the affected product
A successful exploit could allow the attacker to view sensitive information in clear text by accessing the logs on an affected system.
Customers are advised to refer to cisco-sa-duo-infodisc-rLCEqm6T for more information.
- cisco-sa-duo-infodisc-rLCEqm6T -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-infodisc-rLCEqm6T
CVEs related to QID 379534
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-duo-infodisc-rLCEqm6T |
|