PT-2022-11522 · Ping Identity · Pingid Windows Login
Published
2022-04-30
·
Updated
2022-09-03
·
CVE-2021-41992
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PingID Windows Login versions prior to 2.7
Description
A misconfiguration of RSA in PingID Windows Login is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
Recommendations
For versions prior to 2.7, update to version 2.7 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources that rely on the affected MFA mechanism until the update is applied.
Fix
Improper Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pingid Windows Login