CVE-2022-40723

The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
pingidentitypingfederate
11.1.0 ≤
𝑥
≤ 11.1.5
pingidentitypingfederate
11.2.0 ≤
𝑥
≤ 11.2.2
pingidentitypingid_integration_kit
𝑥
< 2.24
pingidentityradius_pcv
3.0.0 ≤
𝑥
< 3.0.2
pingidentityradius_pcv
2.10.0
𝑥
= Vulnerable software versions