A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS client request.
https://www.pingidentity.com/en/resources/downloads/pingfederate.html
https://docs.pingidentity.com/r/en-us/pingid/pingid_integration_kit_2_26_rn