CVE-2022-23717: PingID Windows Login prior to 2.8 denial of service condition
Published Jun 30, 2022
·Updated
PingID Windows Login prior to 2.8 is vulnerable to a denial of service condition on local machines when combined with using offline security keys as part of authentication.
Affected Software
1 affected component
pingidentity Pingid Integration For Windows Login<2.8
Event History
Jun 30, 2022
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-23717?
CVE-2022-23717 refers to a vulnerability in PingID Windows Login prior to version 2.8 that can lead to a denial of service condition on local machines when using offline security keys for authentication.
2
How severe is CVE-2022-23717?
CVE-2022-23717 has a severity rating of medium, with a CVSS score of 5.5.
3
Which software versions are affected by CVE-2022-23717?
PingID Windows Login versions prior to 2.8 are affected by CVE-2022-23717.
4
How can I fix CVE-2022-23717?
To fix CVE-2022-23717, users should update PingID Windows Login to version 2.8 or later.
5
Where can I find more information about CVE-2022-23717?
More information about CVE-2022-23717 can be found in the official documentation at [link].