docs.pingidentity.com
https://docs.pingidentity.com/r/en-us/pingid/davinci_pingid_windows_login_relnotes_2.9 CVE-2022-23721
LOW
PingID integration for Windows login duplicate username collision.
Record summary
CVE-2022-23721 has a selected CVSS score of 3.8 (low).
Description
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-23721