Ping Identity Windows PingId是美国Ping Identity公司的一款可以为应用程序提供安全保障的软件。 Ping Identity Windows PingId 2.9之前版本存在安全漏洞,该漏洞源于当两个具有相同用户名的人在不同时间配置到同一台机器上时,会触发用户名冲突问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ping Identity | unspecified | 2.9 ~ 2.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-40722 | 7.7 HIGH | Misconfiguration of RSA padding for offline MFA in the PingID Adapter for PingFederate. |
| CVE-2022-40725 | 7.3 HIGH | PingID Desktop PIN attempt lockout bypass. |
| CVE-2022-40723 | 6.5 MEDIUM | Configuration-based MFA Bypass in PingID RADIUS PCV. |
| CVE-2022-40724 | 6.4 MEDIUM | Cross-Site Request Forgery on PingFederate Local Identity Profiles Endpoint. |
No comments yet