Lucene search

K

Duo Network Gateway Security Vulnerabilities

cve
cve

CVE-2020-3483

Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL certificates and private keys were not excluded from logging. This issue resulted in certificate and private key information being written out in plain-text to local files on the...

7.1CVSS

6AI Score

0.0004EPSS

2020-10-14 07:15 PM
25
cve
cve

CVE-2018-7340

Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication....

7.5CVSS

8.1AI Score

0.001EPSS

2019-04-17 03:29 PM
28