Duo's vulnerability footprint centers on a narrow range of authentication and access products, primarily the Authentication Proxy and DuoConnect, which handle sensitive credential and session data in trust-critical roles. The observed weakness classes—cleartext storage and transmission of sensitive information, insertion of secrets into log files, and Windows shortcut-following vulnerabilities—reflect the data-handling and system-integration demands of identity and access infrastructure; current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Duo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-1492HIGH The Duo Authentication Proxy installer prior to 5.2.1 did not properly validate file installation paths. This allows an attacker with local user privileges to coerce the installer | Mar 25, 2021 | 7.1 | 23 | NO | NO |
CVE-2023-20207MEDIUM A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive information in clear text on an affected | Jul 12, 2023 | 6.5 | 18 | NO | NO |
CVE-2020-3442MEDIUM The DuoConnect client enables users to establish SSH connections to hosts protected by a DNG instance. When a user initiates an SSH connection to a DNG-protected host for the first | Jul 20, 2020 | 5.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Duo.
Media articles that mention a CVE ID that affects a product developed by Duo — matched by CVE ID, not by vendor name.