CVE-2023-39231

HIGH

PingFederate PingOne MFA Integration Kit - Missing Authentication for MFA Device Pairing

Title source: llm
STIX 2.1

Description

PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.

Scores

CVSS v3 7.3
EPSS 0.0053
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306 CWE-288
Status published
Products (1)
pingidentity/pingone_mfa_integration_kit 2.2
Published Oct 25, 2023
Tracked Since Feb 18, 2026