Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-79r2-xx5c-vqfx

Опубликовано: 01 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.

PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.

EPSS

Процентиль: 76%
0.00949
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
nvd
больше 3 лет назад

PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.

CVSS3: 7.6
fstec
больше 3 лет назад

Уязвимость программного средства многофакторной проверки подлинности приложений (MFA) PingID для Windows, связанная применением устаревших функций, позволяющая нарушителю выполнить атаку «человек посередине» (MITM)

EPSS

Процентиль: 76%
0.00949
Низкий

8.1 High

CVSS3