« Volver al listado

CVE-2021-40329

Estado: ModificadaCrítica (9.8)—

The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-40329",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "responsible-disclosure@pingidentity.com",
      "affectedData": [
        {
          "vendor": "Ping Identity",
          "product": "PingFederate",
          "versions": [
            {
              "status": "affected",
              "version": "9.2.3"
            }
          ]
        },
        {
          "vendor": "Ping Identity",
          "product": "PingFederate",
          "versions": [
            {
              "status": "affected",
              "version": "9.3.3"
            }
          ]
        },
        {
          "vendor": "Ping Identity",
          "product": "PingFederate",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.9"
            }
          ]
        },
        {
          "vendor": "Ping Identity",
          "product": "PingFederate",
          "versions": [
            {
              "status": "affected",
              "version": "10.1.6"
            }
          ]
        },
        {
          "vendor": "Ping Identity",
          "product": "PingFederate",
          "versions": [
            {
              "status": "affected",
              "version": "10.2.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-09-27T17:15:08.653",
  "references": [
    {
      "url": "https://docs.pingidentity.com/bundle/pingfederate-103/page/cou1615333347158.html",
      "source": "responsible-disclosure@pingidentity.com"
    },
    {
      "url": "https://docs.pingidentity.com/bundle/pingfederate-103/page/cou1615333347158.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management."
    },
    {
      "lang": "es",
      "value": "La API de autenticación en Ping Identity PingFederate versiones anteriores a 10.3, maneja inapropiadamente determinados aspectos de la administración de contraseñas externas"
    }
  ],
  "lastModified": "2026-06-17T04:06:44.173",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B18B0A9E-1177-4ADF-A89D-8DB83AE961AA",
              "versionEndExcluding": "10.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "responsible-disclosure@pingidentity.com"
}