CVE-2018-7340

HIGH

Cisco Duo Network Gateway < 1.2.9 - Authentication Bypass via SAML Signature Manipulation

Title source: llm
STIX 2.1

Description

Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://www.kb.cert.org/vuls/id/475445

Scores

CVSS v3 7.5
EPSS 0.0096
EPSS Percentile 56.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-287 CWE-347
Status published
Products (1)
cisco/duo_network_gateway < 1.2.9
Published Apr 17, 2019
Tracked Since Feb 18, 2026