CVE-2023-39231 | PingFederate PingOne MFA IK Device Pairing Second Factor Authentication Bypass
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to exploit this vulnerability to register their own MFA device if they have knowledge of a victim user's first factor credentials.
Conclusion & alert: CVE-2023-39231 is rated Moderate Risk (41.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.14%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2023-39231
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).