PT-2022-11524 · Ping Identity · Pingid Windows Login+1

Published

2022-04-30

·

Updated

2022-05-10

·

CVE-2021-41994

CVSS v3.1

6.6

Medium

VectorAV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PingID iOS app versions prior to 1.19
Description A misconfiguration of RSA in the PingID iOS app is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
Recommendations For versions prior to 1.19, update to version 1.19 or later to resolve the issue. As a temporary workaround, consider restricting the use of the PingID Windows Login feature until the update is applied.

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41994

Affected Products

Pingid Windows Login
Pingid Ios App