Path traversal in Cisco Duo Device Health Application for Windows - CVE-2023-20229

 

Path traversal in Cisco Duo Device Health Application for Windows - CVE-2023-20229

Published: August 25, 2023


Vulnerability identifier: #VU79964
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20229
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in the CryptoService function. A local user can send a specially crafted HTTP request and overwrite arbitrary files on the system, leading to denial of service (DoS) condition.


Affected software

Cisco Duo Device Health Application for Windows

How to mitigate CVE-2023-20229

Install update from vendor's website.

Cisco Duo Device Health Application for Windows - update to 5.2.0

External References

Related Security Bulletins