PingFederate PingOne MFA IK Device Pairing Second Factor Authentication Bypass
Vulnerability Description
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-39231
Credits & Attribution
No credits recorded in the NVD database.
References
More from Ping Identity
View All →Affected Vendor
Ping Identity
View all reports →