A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
2022-04-30T22:15:08.203
2024-11-21T06:27:02.620
Modified
CVSSv3.1: 6.6 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pingidentity | pingid | < 1.19 | Yes |
Application | pingidentity | pingid_windows_login | - | Yes |