A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
2023-04-25T19:15:10.240
2024-11-21T07:21:56.117
Modified
CVSSv3.1: 7.7 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pingidentity | pingfederate | ≤ 11.1.5 | Yes |
Application | pingidentity | pingfederate | ≤ 11.2.2 | Yes |
Application | pingidentity | pingid_adapter_for_pingfederate | < 2.13.2 | Yes |
Application | pingidentity | pingid_integration_kit | < 2.24 | Yes |