A vulnerability in the debug logging function of Cisco Duo Authentication Proxy could allow an authenticated, high-privileged, remote attacker to view sensitive information in a system log file.
This vulnerability is due to insufficient masking of sensitive information before it is written to system log files. An attacker could exploit this vulnerability by accessing logs on an affected system. A successful exploit could allow the attacker to view sensitive information that should be restricted. 
                
            Metrics
Affected Vendors & Products
References
        History
                    Sun, 24 Aug 2025 22:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Duo
         Duo authentication Proxy  | 
|
| Vendors & Products | 
        
        Duo
         Duo authentication Proxy  | 
Wed, 20 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Wed, 20 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability in the debug logging function of Cisco Duo Authentication Proxy could allow an authenticated, high-privileged, remote attacker to view sensitive information in a system log file. This vulnerability is due to insufficient masking of sensitive information before it is written to system log files. An attacker could exploit this vulnerability by accessing logs on an affected system. A successful exploit could allow the attacker to view sensitive information that should be restricted.  | |
| Title | Cisco Duo Authentication Proxy Information Disclosure Vulnerability | |
| Weaknesses | CWE-200 | |
| References | 
         | 
        
  | 
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: cisco
Published: 2025-08-20T16:26:32.520Z
Updated: 2025-08-20T18:43:54.617Z
Reserved: 2024-10-10T19:15:13.256Z
Link: CVE-2025-20345
Updated: 2025-08-20T18:43:50.747Z
Status : Awaiting Analysis
Published: 2025-08-20T17:15:34.850
Modified: 2025-08-22T18:09:17.710
Link: CVE-2025-20345
No data.