Cisco Duo Self-Service Portal Command Injection Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 5.4 Security Advisory

TL;DR 📌

A command injection vulnerability has been identified in the Cisco Duo Self-Service Portal, allowing unauthenticated remote attackers to inject arbitrary commands into emails sent by the service. Cisco has addressed this issue, and no customer action is necessary.

What happened 🕵️‍♂️

A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emails sent by the service. This is due to insufficient input validation. A successful exploit could enable attackers to send emails containing malicious content to unsuspecting users.

Affected products 🖥️

This vulnerability affects the Cisco Duo self-service portal, which is cloud-based.

Fixed software 🔧

Upgrade to at least the first fixed release in your train (or later):

Product / Release Train First Fixed Release Notes
ISE / ISE-PIC 1.0 Initial public release.

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

The highest CVSS score for this vulnerability is 5.4, categorized as MEDIUM severity. While this indicates a moderate risk, the lack of required action from customers mitigates immediate concerns.

Fast facts ⚡

  • Vulnerability ID: CVE-2025-20258
  • CVSS Score: 5.4 (MEDIUM)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  • Exploitation Awareness: No public announcements or malicious use reported.

For leadership 🧭

Executive summary. A flaw in the Cisco Duo Self-Service Portal’s email-sending function could let an outside attacker plant malicious content in messages sent to your users. Cisco has already fixed this on its cloud-hosted service, so no action is required from customers.

Why it matters:

  • The affected component is the cloud-hosted Cisco Duo Self-Service Portal, meaning email notifications sent to end users were the vector, not an on-premises system administrators manage directly.
  • Insufficient input validation allowed command injection into outbound emails, which could be used to deliver malicious content to recipients who trust portal-generated messages.
  • No authentication was required to attempt exploitation, though user interaction was needed, widening the pool of potential senders of tainted emails.
  • Because the service is cloud-based and Cisco has already remediated it, there is no patch to deploy or configuration to change on the customer side.

Now / Next / Later:

  • Now: Confirm with your Cisco Duo administrator that no further action is needed, since the fix has already been applied to the cloud service.
  • Next: Remind help desk and security teams that Duo self-service portal emails were a historical injection vector, so any unusual formatting or links in these messages during the affected period should be reviewed.
  • Later: Include cloud-hosted identity and MFA services like Duo in your vendor patch-tracking process so fixes applied upstream are logged and verified rather than assumed.