A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to invalidate locally created trusted sessions after a reboot of the affected device. An attacker with primary user credentials could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to access the affected device without valid permissions.
History

Mon, 24 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco duo Authentication For Windows Logon And Rdp
Weaknesses CWE-613
CPEs cpe:2.3:a:cisco:duo_authentication_for_windows_logon_and_rdp:*:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco duo Authentication For Windows Logon And Rdp

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-08-01T21:59:41.592Z

Reserved: 2023-11-08T15:08:07.630Z

Link: CVE-2024-20301

cve-icon Vulnrichment

Updated: 2024-08-01T21:59:41.592Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-06T17:15:08.987

Modified: 2025-03-24T13:53:28.940

Link: CVE-2024-20301

cve-icon Redhat

No data.