PT-2025-22397 · Cisco · Cisco Duo

Published

2025-05-21

·

Updated

2025-05-28

·

CVE-2025-20258

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Duo (affected versions not specified)
Description A vulnerability in the self-service portal could allow an unauthenticated, remote attacker to inject arbitrary commands into emails sent by the service. This issue is due to insufficient input validation, allowing an attacker to exploit it by injecting arbitrary commands into a portion of an email. A successful exploit could allow the attacker to send emails containing malicious content to unsuspecting users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06737
CVE-2025-20258

Affected Products

Cisco Duo