SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-40723

The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.

MEDIUM 6.5EPSS 0.52%

Does this matter?

Lower severity and a low EPSS score (0.52%). Track it; it rarely justifies an emergency change on its own.

Description

The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.52% probability · 42th percentile
CISA KEV
Not listed
Weakness
CWE-305, CWE-287
Affected
pingidentity/pingfederate · pingidentity/pingid integration kit · pingidentity/radius pcv
Source
responsible-disclosure@pingidentity.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.