VYPR

Duo

by Cisco Systems, Inc.

CVEs (5)

  • CVE-2023-20123MedApr 5, 2023
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected…

  • CVE-2024-20301MedMar 6, 2024
    risk 0.40cvss 6.2epss 0.00

    A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally created trusted…

  • CVE-2023-20199MedJun 28, 2023
    risk 0.40cvss 6.2epss 0.00

    A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypass secondary authentication and access an affected macOS device. This vulnerability is due to the incorrect handling of responses from Cisco Duo when the…

  • CVE-2022-20662MedSep 30, 2022
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability exists because the assigned user of a smart card is not properly matched with the…

  • CVE-2025-20258MedMay 21, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emails that are sent by the service. This vulnerability is due to insufficient input validation. An attacker could exploit this…