CVE-2020-10654

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
13/05/2020
Last modified:
15/05/2020

Description

Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticating endpoint.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pingidentity:pingid_ssh_integration:*:*:*:*:*:*:*:* 4.0.14 (excluding)