PT-2022-11523 · Ping Identity · Pingid Windows Login+1
Published
2022-04-30
·
Updated
2024-09-04
·
CVE-2021-41993
CVSS v3.1
6.6
Medium
| Vector | AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PingID Android app versions prior to 1.19
Description
The issue is related to a misconfiguration of RSA in the PingID Android app, which makes it vulnerable to pre-computed dictionary attacks. This vulnerability can lead to an offline MFA bypass when using PingID Windows Login. The issue is being actively exploited.
Recommendations
For versions prior to 1.19, update to version 1.19 or later to resolve the issue. As a temporary workaround, consider restricting the use of the PingID Windows Login feature until the update is applied.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pingid Android App
Pingid Windows Login