4.8
CVSSv3

CVE-2021-41993

Published: 30/04/2022 Updated: 10/05/2022
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.8 | Impact Score: 4 | Exploitability Score: 0.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A misconfiguration of RSA in PingID Android app before 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pingidentity pingid

pingidentity pingid windows login -