CVE-2022-23721
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.
Scoring
- Severity
- LOW
- CVSS base score
- 3.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
- EPSS probability
- 0.04%
- CWE
- CWE-694
- Published
- 2023-04-25
- Last modified
- 2026-03-13
Affected products
- Ping Identity unspecified
Weakness type
Related vulnerabilities
- CVE-2026-71327 — Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
- CVE-2026-57024 — Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously
- CVE-2026-5794 — Vulnerability in Cryptobox allows an authenticated user to trigger an account lockout
- CVE-2025-13609 — Keylime: keylime: registrar allows identity takeover via duplicate uuid registration
- CVE-2025-59048 — OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method
- CVE-2024-41146 — Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller...
- CVE-2023-20100 — Cisco IOS XE Software for Wireless LAN Controllers CAPWAP Join Denial of Service Vulnerability
- CVE-2021-3436 — BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known