CVE-2022-40723: Configuration-based MFA Bypass in PingID RADIUS PCV.
Published Apr 25, 2023
·Updated
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
Affected Software
5 affected components
pingidentity Pingfederate>=11.1.0<=11.1.5
pingidentity Pingfederate>=11.2.0<=11.2.2
pingidentity Pingid Integration Kit<2.24
pingidentity Radius Pcv>=3.0.0<3.0.2
pingidentity Radius Pcv=2.10.0
Event History
Apr 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-40723?
CVE-2022-40723 is a vulnerability in the PingID RADIUS PCV adapter for PingFederate.
2
How does CVE-2022-40723 affect PingFederate?
CVE-2022-40723 allows for MFA bypass under certain configurations when using PingFederate with the PingID RADIUS PCV adapter.
3
Which versions of PingFederate are affected by CVE-2022-40723?
PingFederate versions 11.1.0 to 11.1.5 and 11.2.0 to 11.2.2 are affected by CVE-2022-40723.
4
Is the PingID Integration Kit affected by CVE-2022-40723?
Yes, the PingID Integration Kit is affected by CVE-2022-40723 if it is version 2.24 or below.
5
How can I fix CVE-2022-40723?
To fix CVE-2022-40723, update PingFederate to a version that is not affected or apply the necessary security patches provided by Pingidentity.