CVE-2023-39231
HIGHPingFederate PingOne MFA Integration Kit - Missing Authentication for MFA Device Pairing
Title source: llmDescription
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.
References (2)
Core 2
Core References
Scores
CVSS v3
7.3
EPSS
0.0053
EPSS Percentile
40.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-306
CWE-288
Status
published
Products (1)
pingidentity/pingone_mfa_integration_kit
2.2
Published
Oct 25, 2023
Tracked Since
Feb 18, 2026