SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-42000

When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.

MEDIUM 6.5EPSS 0.53%

Does this matter?

Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.

Description

When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.53% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-285
Affected
pingidentity/pingfederate
Source
responsible-disclosure@pingidentity.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.