PingID Adapter是Ping Identity的一款用于身份验证和访问控制的中间件。 PingID Adapter存在安全漏洞,该漏洞源于离线 MFA 容易受到预计算字典攻击,从而导致离线 MFA 被绕过。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ping Identity | PingID Adapter for PingFederate | 2.13.2 ~ 2.13.2 | - |
|
| Ping Identity | PingID Integration Kit (includes PingID Adapter) | 2.24 ~ 2.24 | - |
|
| Ping Identity | PingFederate (includes PingID Adapter) | 11.1.0 ~ 11.1.0* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-40725 | 7.3 HIGH | PingID Desktop PIN attempt lockout bypass. |
| CVE-2022-40723 | 6.5 MEDIUM | Configuration-based MFA Bypass in PingID RADIUS PCV. |
| CVE-2022-40724 | 6.4 MEDIUM | Cross-Site Request Forgery on PingFederate Local Identity Profiles Endpoint. |
| CVE-2022-23721 | 3.8 LOW | PingID integration for Windows login duplicate username collision. |
No comments yet