6.5
CVE-2023-20207
- EPSS 0.06%
- Veröffentlicht 12.07.2023 14:15:09
- Zuletzt bearbeitet 21.11.2024 07:40:50
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability exists because certain unencrypted credentials are stored. An attacker could exploit this vulnerability by accessing the logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to view sensitive information in clear text.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Duo ≫ Authentication Proxy Version5.8.1
Duo ≫ Authentication Proxy Version6.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.173 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| psirt@cisco.com | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.