« Volver al listado

CVE-2022-40723

Estado: ModificadaMedia (6.5)—

The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-40723",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-40723",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-04T14:48:50.451839Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "responsible-disclosure@pingidentity.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "responsible-disclosure@pingidentity.com",
      "affectedData": [
        {
          "vendor": "Ping Identity",
          "product": "PingID Radius PCV",
          "versions": [
            {
              "status": "affected",
              "version": "2.10.0"
            },
            {
              "status": "affected",
              "version": "3.0.0",
              "lessThan": "3.0.0*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.0.2",
              "versionType": "custom",
              "lessThanOrEqual": "3.0.2"
            }
          ]
        },
        {
          "vendor": "Ping Identity",
          "product": "PingID Integration Kit (includes Radius PCV)",
          "versions": [
            {
              "status": "affected",
              "version": "2.24",
              "lessThan": "2.24",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Ping Identity",
          "product": "PingFederate (includes Radius PCV)",
          "versions": [
            {
              "status": "affected",
              "version": "11.1.0",
              "lessThan": "11.1.0*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "11.1.5",
              "versionType": "custom",
              "lessThanOrEqual": "11.1.5"
            },
            {
              "status": "affected",
              "version": "11.2.0",
              "lessThan": "11.2.0*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "11.2.2",
              "versionType": "custom",
              "lessThanOrEqual": "11.2.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-04-25T19:15:10.310",
  "references": [
    {
      "url": "https://docs.pingidentity.com/r/en-us/pingid/pingid_integration_kit_2_19_rn",
      "tags": [
        "Release Notes"
      ],
      "source": "responsible-disclosure@pingidentity.com"
    },
    {
      "url": "https://docs.pingidentity.com/r/en-us/pingid/pingid_integration_kit_2_19_rn",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "responsible-disclosure@pingidentity.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-305"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations."
    }
  ],
  "lastModified": "2026-06-17T05:01:54.917",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F085AB7-29E3-4CC6-88C6-49EF87B1E7E9",
              "versionEndIncluding": "11.1.5",
              "versionStartIncluding": "11.1.0"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F76BB82-2AE0-4330-84E7-BBFFABF030C0",
              "versionEndIncluding": "11.2.2",
              "versionStartIncluding": "11.2.0"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:pingid_integration_kit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0D3BE72-98EE-4FE4-BF80-CDD66F495AC1",
              "versionEndExcluding": "2.24"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:radius_pcv:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A97675A-6B44-4AB9-AC7A-D67153A0273C",
              "versionEndExcluding": "3.0.2",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:radius_pcv:2.10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73EC03B9-23AE-4E5C-A7AD-44D10E3997FA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "responsible-disclosure@pingidentity.com"
}