Lucene search

K
nvd[email protected]NVD:CVE-2023-39930
HistoryOct 25, 2023 - 6:17 p.m.

CVE-2023-39930

2023-10-2518:17:29
CWE-306
CWE-288
web.nvd.nist.gov
1
pingfederate
authentication bypass
radius
mschap
vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0.001

Percentile

43.8%

A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.

Affected configurations

Nvd
Node
pingidentitypingid_radius_pcvRange3.0.03.0.3
VendorProductVersionCPE
pingidentitypingid_radius_pcv*cpe:2.3:a:pingidentity:pingid_radius_pcv:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0.001

Percentile

43.8%

Related for NVD:CVE-2023-39930