PT-2022-11525 · Ping Identity · Pingid Mac Login
Published
2022-06-30
·
Updated
2022-07-15
·
CVE-2021-41995
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PingID Mac Login versions prior to 1.1
Description
A misconfiguration of RSA in PingID Mac Login is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
Recommendations
For versions prior to 1.1, update to version 1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources that rely on PingID Mac Login for MFA until the update can be applied.
Fix
Improper Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pingid Mac Login