Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-40722


A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.


Published

2023-04-25T19:15:10.240

Last Modified

2024-11-21T07:21:56.117

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.7 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-780
  • Type: Primary
    CWE-327

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application pingidentity pingfederate ≤ 11.1.5 Yes
Application pingidentity pingfederate ≤ 11.2.2 Yes
Application pingidentity pingid_adapter_for_pingfederate < 2.13.2 Yes
Application pingidentity pingid_integration_kit < 2.24 Yes

References