5.8
CVSSv3

CVE-2022-40722

Published: 25/04/2023 Updated: 04/05/2023
CVSS v3 Base Score: 5.8 | Impact Score: 4 | Exploitability Score: 1.3
VMScore: 0

Vulnerability Summary

A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pingidentity pingid integration kit

pingidentity pingfederate

pingidentity pingid adapter for pingfederate