A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally created trusted sessions after a reboot of the affected device. An attacker with primary user credentials could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to access the affected device without valid permissions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-03-06T16:28:22.087Z

Updated: 2024-08-01T21:59:41.592Z

Reserved: 2023-11-08T15:08:07.630Z

Link: CVE-2024-20301

cve-icon Vulnrichment

Updated: 2024-08-01T21:59:41.592Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-06T17:15:08.987

Modified: 2024-11-21T08:52:17.907

Link: CVE-2024-20301

cve-icon Redhat

No data.