« Volver al listado

CVE-2025-20628

Estado: Pendiente de análisisMedia (6.9)—

An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode. This means attackers can spoof a client-mode RCS (if one exists) to intercept and/or modify an identity’s security-relevant properties, such as passwords and account recovery information. This issue is exploitable only when an RCS is configured to run in client mode.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-20628",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-20628",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-08T15:16:23.302687Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "responsible-disclosure@pingidentity.com",
        "cvssData": {
          "Safety": "PRESENT",
          "version": "4.0",
          "Recovery": "USER",
          "baseScore": 6.9,
          "Automatable": "YES",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "CONCENTRATED",
          "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Red",
          "exploitMaturity": "UNREPORTED",
          "providerUrgency": "RED",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "MODERATE",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "responsible-disclosure@pingidentity.com",
      "affectedData": [
        {
          "vendor": "Ping Identity",
          "product": "PingIDM",
          "versions": [
            {
              "status": "affected",
              "version": "7.5.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.4.0",
              "versionType": "custom",
              "lessThanOrEqual": "7.4.1"
            },
            {
              "status": "affected",
              "version": "7.3.0",
              "versionType": "custom",
              "lessThanOrEqual": "7.3.1"
            },
            {
              "status": "affected",
              "version": "7.2.0",
              "versionType": "custom",
              "lessThanOrEqual": "7.2.2"
            },
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "7.1.*"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-07T23:16:27.040",
  "references": [
    {
      "url": "https://backstage.forgerock.com/knowledge/advisories/article/a14305629?rev=_newest",
      "source": "responsible-disclosure@pingidentity.com"
    },
    {
      "url": "https://backstage.pingidentity.com/downloads/browse/idm/featured",
      "source": "responsible-disclosure@pingidentity.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "responsible-disclosure@pingidentity.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1220"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode. This means attackers can spoof a client-mode RCS (if one exists) to intercept and/or modify an identity’s security-relevant properties, such as passwords and account recovery information. This issue is exploitable only when an RCS is configured to run in client mode."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de granularidad insuficiente en el control de acceso existe en PingIDM (anteriormente ForgeRock Identity Management) donde los administradores no pueden configurar correctamente las reglas de acceso para los Servidores de Conector Remoto (RCS) que se ejecutan en modo cliente. Esto significa que los atacantes pueden suplantar un RCS en modo cliente (si existe uno) para interceptar y/o modificar las propiedades relevantes para la seguridad de una identidad, como contraseñas e información de recuperación de cuenta. Este problema es explotable solo cuando un RCS está configurado para ejecutarse en modo cliente."
    }
  ],
  "lastModified": "2026-07-24T23:10:00.563",
  "sourceIdentifier": "responsible-disclosure@pingidentity.com"
}