CVE-2023-20207

A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencrypted credentials are stored. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to view sensitive information in clear text.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:duo:authentication_proxy:5.8.1:*:*:*:*:*:*:*
cpe:2.3:a:duo:authentication_proxy:6.0.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 4.9
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-auth-info-JgkSWBLz - Vendor Advisory () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-auth-info-JgkSWBLz - Vendor Advisory

21 Jul 2023, 16:45

Type Values Removed Values Added
CWE CWE-312
References (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-auth-info-JgkSWBLz - (MISC) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-auth-info-JgkSWBLz - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Duo
Duo authentication Proxy
CPE cpe:2.3:a:duo:authentication_proxy:5.8.1:*:*:*:*:*:*:*
cpe:2.3:a:duo:authentication_proxy:6.0.0:*:*:*:*:*:*:*

12 Jul 2023, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-12 14:15

Updated : 2024-11-21 07:40


NVD link : CVE-2023-20207

Mitre link : CVE-2023-20207

CVE.ORG link : CVE-2023-20207


JSON object : View

Products Affected

duo

  • authentication_proxy
CWE
CWE-532

Insertion of Sensitive Information into Log File

CWE-312

Cleartext Storage of Sensitive Information