Cisco Duo Authentication Proxy Information Disclosure Vulnerability
TL;DR 📌
A medium-severity information disclosure vulnerability has been identified in the Cisco Duo Authentication Proxy. This flaw allows authenticated, high-privileged remote attackers to view sensitive information in system log files. There are no workarounds available, and users are advised to upgrade to fixed software versions.
What happened 🕵️♂️
A vulnerability in the debug logging function of the Cisco Duo Authentication Proxy could allow an authenticated, high-privileged remote attacker to access sensitive information that is inadequately masked in system log files. This could lead to unauthorized disclosure of sensitive data, which should remain restricted. Cisco has released software updates to address this vulnerability.
Affected products 🖥️
The vulnerability affects the following versions of Cisco Duo Authentication Proxy:
- 5.8.2 and earlier
- 6.5.1 and earlier
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 5.8.2 and earlier | Migrate to a fixed release. | |
| 6.5.1 and earlier | 6.5.2 | |
| 1.0 | Initial public release. | |
| Cisco Duo Authentication Proxy | 6.5.2 | 5.8.2 and earlier, 6.5.1 and earlier |
Workarounds 🧯
There are no workarounds available to address this vulnerability. Cisco recommends deleting log files from the system where the Cisco Duo Authentication Proxy is installed and any other systems where logs may be stored after upgrading.
Risk in context 🎯
With a CVSS score of 4.9, this vulnerability is classified as medium severity. While it requires high privileges for exploitation, the risk of sensitive information exposure remains significant, particularly for organizations that rely on the Duo Authentication Proxy for secure access management.
Fast facts ⚡
- Vulnerability: Information Disclosure in Cisco Duo Authentication Proxy
- CVSS Score: 4.9 (Medium)
- Exploitation: Requires authenticated, high-privileged access
- Impact: Sensitive information exposure in log files
- Workarounds: None available
For leadership 🧭
Executive summary. An authenticated, high-privileged user on systems running Cisco Duo Authentication Proxy could read sensitive data left unmasked in debug logs, including on any secondary system where those logs are copied or forwarded. There is no exploitation activity known, but since there is no workaround, this should be scheduled for the next available change window rather than left indefinitely.
Why it matters:
- Debug logs from the Duo Authentication Proxy can retain sensitive information that should be masked, exposing it to anyone with the elevated access needed to read the log files.
- Because logs are often copied to central logging or SIEM systems, the exposure isn’t limited to the proxy host itself – anywhere those logs land is affected.
- No workaround exists; the only mitigations are upgrading and deleting existing log files, so old logs remain a risk until they are removed.
- Versions 5.8.2 and earlier and 6.5.1 and earlier are affected, meaning most deployments that haven’t recently upgraded are in scope.
Now / Next / Later:
- Now: Identify all Cisco Duo Authentication Proxy instances and confirm their version against 5.8.2 and earlier or 6.5.1 and earlier.
- Next: Upgrade to 6.5.2 (or the first fixed release for your train) in the next change window, then delete existing log files from the proxy host and any system where those logs have been copied or stored.
- Later: Add Duo Authentication Proxy version and patch status to routine infrastructure audits, and review log retention/forwarding practices to limit how far sensitive log data propagates before it can be purged.