Cyber Security News

Cisco Duo Device Health App Flaw Allows Directory Traversal Attacks

The CryptoService function in the Cisco Duo Device Health Application for Windows has a vulnerability tracked as (CVE-2023-20229).

This might allow a low-privileged attacker to carry out directory traversal attacks and overwrite arbitrary files on a susceptible device.

Directory traversal, also known as Path traversal, is a type of HTTP attack that enables attackers to access restricted directories and run commands outside of the web server’s root directory.

An attacker just requires a web browser and some knowledge of where to look for any default files and directories on the system to conduct a directory traversal attack.

Cisco has issued software upgrades to address this vulnerability. There are no workarounds for this issue.

Details of the Vulnerability

The vulnerability tagged as (CVE-2023-20229) with a CVSS score of 7.1 with high severity range is caused due to insufficient input validation.

“An attacker could exploit this vulnerability by executing a directory traversal attack on an affected host,” Cisco said in its security advisory.

Upon successful exploitation, an attacker may be able to overwrite arbitrary files with SYSTEM-level privileges using a cryptographic key, causing a DoS issue or data loss on the impacted system.

Affected Products

The Cisco Duo Device Health Application for Windows is impacted. Cisco also confirms that this vulnerability does not impact Cisco Duo Device Health Application for macOS.

Fixes Available

Cisco has issued free software upgrades available to fix the problem.

Customers are encouraged to upgrade to an applicable fixed software release as soon as possible to remain secure.

Keep informed about the latest Cyber Security News by following us on GoogleNewsLinkedinTwitter, and Facebook.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

4 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

5 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

6 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

6 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

7 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

7 hours ago