PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ping Identity

Published: 2023-10-24T19:56:06.690Z

Updated: 2024-09-11T17:39:35.873Z

Reserved: 2023-07-25T20:13:14.885Z

Link: CVE-2023-39231

cve-icon Vulnrichment

Updated: 2024-08-02T18:02:06.576Z

cve-icon NVD

Status : Modified

Published: 2023-10-25T18:17:29.030

Modified: 2024-11-21T08:14:57.667

Link: CVE-2023-39231

cve-icon Redhat

No data.