CVE-2023-20207

A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencrypted credentials are stored. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to view sensitive information in clear text.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:duo:authentication_proxy:5.8.1:*:*:*:*:*:*:*
cpe:2.3:a:duo:authentication_proxy:6.0.0:*:*:*:*:*:*:*

History

25 Jan 2024, 17:15

Type Values Removed Values Added
CWE CWE-532

21 Jul 2023, 16:45

Type Values Removed Values Added
References (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-auth-info-JgkSWBLz - (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-auth-info-JgkSWBLz - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:duo:authentication_proxy:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:duo:authentication_proxy:5.8.1:*:*:*:*:*:*:*
CWE CWE-312
First Time Duo
Duo authentication Proxy

12 Jul 2023, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-12 14:15

Updated : 2024-01-25 17:15


NVD link : CVE-2023-20207

Mitre link : CVE-2023-20207

CVE.ORG link : CVE-2023-20207


JSON object : View

Products Affected

duo

  • authentication_proxy
CWE
CWE-312

Cleartext Storage of Sensitive Information

CWE-532

Insertion of Sensitive Information into Log File