PT-2022-11524 · Ping Identity · Pingid Windows Login+1
Published
2022-04-30
·
Updated
2022-05-10
·
CVE-2021-41994
CVSS v3.1
6.6
Medium
| Vector | AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PingID iOS app versions prior to 1.19
Description
A misconfiguration of RSA in the PingID iOS app is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
Recommendations
For versions prior to 1.19, update to version 1.19 or later to resolve the issue. As a temporary workaround, consider restricting the use of the PingID Windows Login feature until the update is applied.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pingid Windows Login
Pingid Ios App