Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54r4-ppj3-fq8f

Опубликовано: 01 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the local Java service using multiple attack vectors. A successful attack can lead to code executed as SYSTEM by the PingID Windows Login application, or even a denial of service for offline security key authentication.

PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the local Java service using multiple attack vectors. A successful attack can lead to code executed as SYSTEM by the PingID Windows Login application, or even a denial of service for offline security key authentication.

EPSS

Процентиль: 13%
0.00043
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-287
CWE-288
CWE-306

Связанные уязвимости

CVSS3: 7.2
nvd
больше 3 лет назад

PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the local Java service using multiple attack vectors. A successful attack can lead to code executed as SYSTEM by the PingID Windows Login application, or even a denial of service for offline security key authentication.

CVSS3: 7.2
fstec
больше 3 лет назад

Уязвимость программного средства многофакторной проверки подлинности приложений (MFA) PingID для Windows, связанная с ошибками при проверке подлинность связи с локальной службой Java, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 13%
0.00043
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-287
CWE-288
CWE-306