CVE-2024-20301
A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This
Description
A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally created trusted sessions after a reboot of the affected device. An attacker with primary user credentials could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to access the affected device without valid permissions.
Weakness: CWE-287
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Duo | Identity / IAM / MFA | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Duo
Vendor advisory
cisco-sa-duo-win-bypass-pn42KKBm
Cisco Duo Authentication for Windows Logon and RDP Authentication Bypass Vulnerability
Cisco’s rating: Medium (advisory CVSS 6.2) · Published Mar 6, 2024
Bug ID: CSCwi57924
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from