A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally created trusted sessions after a reboot of the affected device. An attacker with primary user credentials could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to access the affected device without valid permissions.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: cisco

Published: 2024-03-06T16:28:22.087Z

Updated: 2024-06-04T17:40:41.658Z

Reserved: 2023-11-08T15:08:07.630Z


Link: CVE-2024-20301

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-03-06T17:15:08.987

Modified: 2024-03-07T13:52:27.110


Link: CVE-2024-20301

JSON object: View

cve-icon Redhat Information

No data.

CWE