CVE-2022-40723

EUVD-2022-43992
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Ping IdentityCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:H/RL:U/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
pingidentitypingfederate
11.1.0 ≤
𝑥
≤ 11.1.5
pingidentitypingfederate
11.2.0 ≤
𝑥
≤ 11.2.2
pingidentitypingid_integration_kit
𝑥
< 2.24
pingidentityradius_pcv
3.0.0 ≤
𝑥
< 3.0.2
pingidentityradius_pcv
2.10.0
𝑥
= Vulnerable software versions