SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-23720

Using sensitive full permissions properties file outside of a privileged trust boundary leads to an increased risk of exposure or discovery, and an attacker could leverage these credentials to perform administrative actions against PingID APIs or…

HIGH 8.2EPSS 0.24%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly deploy administrator privileged PingID API credentials, such as those typically used by PingFederate, into PingID Windows Login user endpoints. Using sensitive full permissions properties file outside of a privileged trust boundary leads to an increased risk of exposure or discovery, and an attacker could leverage these credentials to perform administrative actions against PingID APIs or endpoints.

CVSS 3.1
8.2 HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
0.24% probability · 16th percentile
CISA KEV
Not listed
Weakness
CWE-288, CWE-648, CWE-269
Affected
pingidentity/pingid integration for windows login
Source
responsible-disclosure@pingidentity.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.