Lucene search

K
cvePing IdentityCVE-2023-39930
HistoryOct 25, 2023 - 6:17 p.m.

CVE-2023-39930

2023-10-2518:17:29
CWE-306
CWE-288
Ping Identity
web.nvd.nist.gov
13
cve-2023-39930
pingfederate
pingid
radius
pcv
authentication bypass
mschap
radius client request
vulnerability
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

43.8%

A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.

Affected configurations

Nvd
Node
pingidentitypingid_radius_pcvRange3.0.03.0.3
VendorProductVersionCPE
pingidentitypingid_radius_pcv*cpe:2.3:a:pingidentity:pingid_radius_pcv:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "PingID Radius PCV",
    "vendor": "Ping Identity",
    "versions": [
      {
        "lessThan": "3.0.3",
        "status": "affected",
        "version": "3.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

43.8%

Related for CVE-2023-39930