PT-2022-11523 · Ping Identity · Pingid Windows Login+1

Published

2022-04-30

·

Updated

2024-09-04

·

CVE-2021-41993

CVSS v3.1

6.6

Medium

VectorAV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PingID Android app versions prior to 1.19
Description The issue is related to a misconfiguration of RSA in the PingID Android app, which makes it vulnerable to pre-computed dictionary attacks. This vulnerability can lead to an offline MFA bypass when using PingID Windows Login. The issue is being actively exploited.
Recommendations For versions prior to 1.19, update to version 1.19 or later to resolve the issue. As a temporary workaround, consider restricting the use of the PingID Windows Login feature until the update is applied.

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2021-41993

Affected Products

Pingid Android App
Pingid Windows Login