CVE-2022-23720 affects PingID Windows Login versions prior to 2.8, where the software fails to alert or halt operation when provisioned with a full permissions PingID properties file. This allows IT administrators to mistakenly deploy highly privileged PingID API credentials to user endpoints, increasing the risk of exposure. With a CVSS score of 8.2 (HIGH), this vulnerability could allow an attacker with high privileges and local access to achieve high confidentiality, integrity, and availability impacts by leveraging these exposed credentials for administrative actions against PingID APIs. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8CPE matchmatch criteria | cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.