Описание
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.
Ссылки
- Release NotesVendor Advisory
- ProductVendor Advisory
- Release NotesVendor Advisory
- ProductVendor Advisory
Уязвимые конфигурации
EPSS
7.6 High
CVSS3
8.1 High
CVSS3
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.
Уязвимость программного средства многофакторной проверки подлинности приложений (MFA) PingID для Windows, связанная применением устаревших функций, позволяющая нарушителю выполнить атаку «человек посередине» (MITM)
EPSS
7.6 High
CVSS3
8.1 High
CVSS3
9.3 Critical
CVSS2