CVE-2025-20628
An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode. This means attackers can spoof a client-mode RCS (if one exists) to intercept and/or modify an identity’s security-relevant properties, such as passwords and account recovery information. This issue is exploitable only when an RCS is configured to run in client mode.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Red
- Puntuación base: 6.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.24%
- Percentil entre todas las CVEs puntuadas: 13
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-1220
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-20628",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-20628",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-04-08T15:16:23.302687Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "responsible-disclosure@pingidentity.com",
"cvssData": {
"Safety": "PRESENT",
"version": "4.0",
"Recovery": "USER",
"baseScore": 6.9,
"Automatable": "YES",
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"valueDensity": "CONCENTRATED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Red",
"exploitMaturity": "UNREPORTED",
"providerUrgency": "RED",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "MODERATE",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "responsible-disclosure@pingidentity.com",
"affectedData": [
{
"vendor": "Ping Identity",
"product": "PingIDM",
"versions": [
{
"status": "affected",
"version": "7.5.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.4.0",
"versionType": "custom",
"lessThanOrEqual": "7.4.1"
},
{
"status": "affected",
"version": "7.3.0",
"versionType": "custom",
"lessThanOrEqual": "7.3.1"
},
{
"status": "affected",
"version": "7.2.0",
"versionType": "custom",
"lessThanOrEqual": "7.2.2"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "7.1.*"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-04-07T23:16:27.040",
"references": [
{
"url": "https://backstage.forgerock.com/knowledge/advisories/article/a14305629?rev=_newest",
"source": "responsible-disclosure@pingidentity.com"
},
{
"url": "https://backstage.pingidentity.com/downloads/browse/idm/featured",
"source": "responsible-disclosure@pingidentity.com"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "responsible-disclosure@pingidentity.com",
"description": [
{
"lang": "en",
"value": "CWE-1220"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode. This means attackers can spoof a client-mode RCS (if one exists) to intercept and/or modify an identity’s security-relevant properties, such as passwords and account recovery information. This issue is exploitable only when an RCS is configured to run in client mode."
},
{
"lang": "es",
"value": "Una vulnerabilidad de granularidad insuficiente en el control de acceso existe en PingIDM (anteriormente ForgeRock Identity Management) donde los administradores no pueden configurar correctamente las reglas de acceso para los Servidores de Conector Remoto (RCS) que se ejecutan en modo cliente. Esto significa que los atacantes pueden suplantar un RCS en modo cliente (si existe uno) para interceptar y/o modificar las propiedades relevantes para la seguridad de una identidad, como contraseñas e información de recuperación de cuenta. Este problema es explotable solo cuando un RCS está configurado para ejecutarse en modo cliente."
}
],
"lastModified": "2026-07-24T23:10:00.563",
"sourceIdentifier": "responsible-disclosure@pingidentity.com"
}