A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
2022-06-30T20:15:08.127
2024-11-21T06:27:02.763
Modified
CVSSv3.1: 7.7 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pingidentity | pingid_integration_for_mac_login | < 1.1 | Yes |
Operating System | apple | macos | - | No |