Beveiligingsadvies

CVE-2023-39231

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-10-24 19:56:06
Laatst bijgewerkt 2024-09-11 17:39:35
Toegewezen door Ping Identity
CVSS-score 7.3
Status PUBLISHED

Beschrijving

PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.