CVE-2022-23725

HIGH

PingID Integration for Windows Login < 2.8 - Insufficiently Protected Credentials via Registry Permissions

Title source: llm
STIX 2.1

Description

PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.

References (2)

Core 2

Scores

CVSS v3 7.7
EPSS 0.0021
EPSS Percentile 10.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Details

CWE
CWE-522 CWE-288 CWE-732
Status published
Products (1)
pingidentity/pingid_integration_for_windows_login < 2.8
Published Jun 30, 2022
Tracked Since Feb 18, 2026