CVE-2023-40356: Ping Identity Pingone MFA Integration Kit For Pingfederate

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under certain conditions, this configuration could allow for a new MFA device to be paired with a target user account without requiring second-factor authentication from the target’s existing registered devices. A threat actor might be able to exploit this vulnerability to register their own MFA device with a target user’s account if they have existing knowledge of the target user’s first factor credential.

Affected products

  • Ping Identity Pingone MFA Integration Kit For Pingfederate: before 2.3.1 (fixed in 2.3.1)
  • Pingone Pingone MFA Intergration Kit For Pingfederate: before 2.3.1 (fixed in 2.3.1)

Published 2024-07-09. Last modified 2026-06-17.