VendorsCiscoduo_authentication_for_windows_logon_and_rdpany version
Vulnerabilities

Cisco Duo Authentication for Windows Logon any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2020-3427
Duo Authentication for Windows Logon and RDP Privilege Escalation Vulnerability
Published 2020-10-14 · Modified
7.8EPSS 0.003
CVE-2023-20123
Cisco Duo Authentication for macOS and Duo Authentication for Windows Logon Offline Credentials Replay Vulnerability
Published 2023-04-05 · Modified
6.3EPSS 0.002
CVE-2024-20301
A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally created trusted sessions after a reboot of the affected device. An attacker with primary user credentials could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to access the affected device without valid permissions.
Published 2024-03-06 · Analyzed
6.2EPSS 0.003
CVE-2024-20292
A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. This vulnerability is due to improper storage of an unencrypted registry key in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system. A successful exploit could allow the attacker to view sensitive information in clear text.
Published 2024-03-06 · Analyzed
5.5EPSS 0.001