CVE-2023-40356: Ping Identity Pingone MFA Integration Kit For Pingfederate
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA configuration. Under certain conditions, this configuration could allow for a new MFA device to be paired with a target user account without requiring second-factor authentication from the target’s existing registered devices. A threat actor might be able to exploit this vulnerability to register their own MFA device with a target user’s account if they have existing knowledge of the target user’s first factor credential.
Affected products
- Ping Identity Pingone MFA Integration Kit For Pingfederate: before 2.3.1 (fixed in 2.3.1)
- Pingone Pingone MFA Intergration Kit For Pingfederate: before 2.3.1 (fixed in 2.3.1)
Published 2024-07-09. Last modified 2026-06-17.