CVE-2022-40723
Published Apr 25, 2023The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
Vendor/product archive
2 CVEs tagged to pingidentity / pingid_integration_kit — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed diction…