VendorsPing Identitypingid_integration_for_windows_loginall versions
Vulnerabilities

Ping Identity PingID Integration for Windows Login

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-23718
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution
Published 2022-06-30 · Modified
9.3EPSS 0.021
CVE-2022-23720
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file
Published 2022-06-30 · Modified
8.2EPSS 0.002
CVE-2022-23724
PingID Integration for Windows Login MFA Bypass
Published 2022-05-04 · Modified
8.1EPSS 0.004
CVE-2020-25826
PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe.
Published 2020-09-23 · Modified
7.8EPSS 0.004
CVE-2021-41992
PingID Windows Login RSA cryptographic weakness with possible offline MFA bypass
Published 2022-04-30 · Modified
7.7EPSS 0.005
CVE-2022-23725
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances
Published 2022-06-30 · Modified
7.7EPSS 0.002
CVE-2022-23719
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests
Published 2022-06-30 · Modified
7.2EPSS 0.003
CVE-2022-23717
PingID Windows Login prior to 2.8 denial of service condition
Published 2022-06-30 · Modified
5.5EPSS 0.002
CVE-2022-23721
PingID integration for Windows login duplicate username collision.
Published 2023-04-25 · Modified
3.8EPSS 0.002