First published: Thu Jun 30 2022(Updated: )
PingID Windows Login prior to 2.8 is vulnerable to a denial of service condition on local machines when combined with using offline security keys as part of authentication.
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Pingid Integration For Windows Login | <2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23717 refers to a vulnerability in PingID Windows Login prior to version 2.8 that can lead to a denial of service condition on local machines when using offline security keys for authentication.
CVE-2022-23717 has a severity rating of medium, with a CVSS score of 5.5.
PingID Windows Login versions prior to 2.8 are affected by CVE-2022-23717.
To fix CVE-2022-23717, users should update PingID Windows Login to version 2.8 or later.
More information about CVE-2022-23717 can be found in the official documentation at [link].