PT-2022-16228 · Ping Identity · Pingfederate Pingone Mfa Integration Kit

Published

2022-05-02

·

Updated

2022-09-03

·

CVE-2022-23723

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PingFederate PingOne MFA Integration Kit (affected versions not specified)
Description An MFA bypass issue exists when adapter HTML templates are used as part of an authentication flow. This allows for potential bypass of multi-factor authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-23723

Affected Products

Pingfederate Pingone Mfa Integration Kit