CVE-2025-20628: Insufficient granularity of access control for Remote Connector Servers in client mode
An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode. This means attackers can spoof a client-mode RCS (if one exists) to intercept and/or modify an identity’s security-relevant properties, such as passwords and account recovery information. This issue is exploitable only when an RCS is configured to run in client mode.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Secure the /openicf endpoint using the new access and authentication configuration options (per Ping’s “migration dependent features” guidance referenced in the material).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20628?
The severity of CVE-2025-20628 is medium with a CVSS score of 6.9.
How do I fix CVE-2025-20628?
To fix CVE-2025-20628, upgrade to a fixed version of PingIDM and secure the /openicf endpoint with new access and authentication configurations.
What type of vulnerability is CVE-2025-20628?
CVE-2025-20628 is classified as an insufficient granularity of access control vulnerability.
What impact does CVE-2025-20628 have on Remote Connector Servers?
CVE-2025-20628 allows attackers to spoof a client-mode Remote Connector Server due to inadequate access rule configurations.
What software is affected by CVE-2025-20628?
CVE-2025-20628 affects Ping Identity's PingIDM (formerly ForgeRock Identity Management).