CVE-2022-23724

MEDIUM

PingIdentity PingID Integration for Windows Login <= 2.4.2 - Authentication Bypass

Title source: llm
STIX 2.1

Description

Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.

References (2)

Core 2
Core References
Product, Vendor Advisory x_refsource_misc
https://www.pingidentity.com/en/resources/downloads/pingid.html

Scores

CVSS v3 6.4
EPSS 0.0041
EPSS Percentile 32.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

Details

CWE
CWE-310 CWE-288 CWE-798
Status published
Products (1)
pingidentity/pingid_integration_for_windows_login < 2.4.2
Published May 04, 2022
Tracked Since Feb 18, 2026