CVE-2022-40725: PingID Desktop PIN attempt lockout bypass.
Published Apr 25, 2023
·Updated
PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout is activated.
Affected Software
1 affected component
pingidentity Desktop<1.7.4
Event History
Apr 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-40725?
CVE-2022-40725 is a vulnerability in PingID Desktop that allows an attacker to bypass the maximum PIN attempts before the time-based lockout is activated.
2
What is the severity of CVE-2022-40725?
CVE-2022-40725 has a severity rating of 6.1 (high).
3
How can CVE-2022-40725 be exploited?
CVE-2022-40725 can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout is activated.
4
What is the affected software for CVE-2022-40725?
The affected software for CVE-2022-40725 is PingID Desktop versions prior to 1.7.4.
5
How can I fix CVE-2022-40725?
To fix CVE-2022-40725, update PingID Desktop to the latest released version 1.7.4.