CVE Vulnerabilities

CVE-2022-40723

Improper Authentication

Published: Apr 25, 2023 | Modified: May 04, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Pingfederate Pingidentity 11.1.0 (including) 11.1.5 (including)
Pingfederate Pingidentity 11.2.0 (including) 11.2.2 (including)
Pingid_integration_kit Pingidentity * 2.24 (excluding)
Radius_pcv Pingidentity 3.0.0 (including) 3.0.2 (excluding)
Radius_pcv Pingidentity 2.10.0 (including) 2.10.0 (including)

Potential Mitigations

References