PingFederate PingOne MFA IK Device Pairing Second Factor Authentication Bypass
CVE-2023-39231
7.3HIGH
What is CVE-2023-39231?
The PingFederate solution utilizing the PingOne MFA adapter has a security vulnerability that permits unauthorized pairing of a new MFA device. This flaw arises because the system does not enforce second-factor authentication from an existing registered device. Attackers with access to a victim's primary authentication credentials can exploit this vulnerability to register and operate their own MFA device, potentially compromising user accounts and sensitive information.
Affected Version(s)
PingOne MFA Integration Kit 2.2