TROYANOSYVIRUS
Back to CVEs

CVE-2023-39231

HIGH
7.3

Description

PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.

CVE Details

CVSS v3.1 Score7.3
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
Published10/25/2023
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

pingidentity:pingone_mfa_integration_kit

Weaknesses (CWE)

CWE-288CWE-306

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.