PingID Adapter是Ping Identity的一款用于身份验证和访问控制的中间件。 PingID Adapter存在安全漏洞,该漏洞源于支持使用 PingID MFA 进行 RADIUS 身份验证,在某些配置下容易受到 MFA 绕过攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ping Identity | PingID Radius PCV | 2.10.0 | - |
|
| Ping Identity | PingID Integration Kit (includes Radius PCV) | 2.24 ~ 2.24 | - |
|
| Ping Identity | PingFederate (includes Radius PCV) | 11.1.0 ~ 11.1.0* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-40722 | 7.7 HIGH | Misconfiguration of RSA padding for offline MFA in the PingID Adapter for PingFederate. |
| CVE-2022-40725 | 7.3 HIGH | PingID Desktop PIN attempt lockout bypass. |
| CVE-2022-40724 | 6.4 MEDIUM | Cross-Site Request Forgery on PingFederate Local Identity Profiles Endpoint. |
| CVE-2022-23721 | 3.8 LOW | PingID integration for Windows login duplicate username collision. |
No comments yet