VYPR

PingIDM

by Pingidentity

CVEs (2)

  • CVE-2020-10654CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticating endpoint.

  • CVE-2022-23724MedMay 4, 2022
    risk 0.42cvss 6.4epss 0.00

    Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.