CVE-2022-40722
25.04.2023, 19:15
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.Enginsight
Vendor | Product | Version |
---|---|---|
pingidentity | pingfederate | 11.1.0 ≤ 𝑥 ≤ 11.1.5 |
pingidentity | pingfederate | 11.2.0 ≤ 𝑥 ≤ 11.2.2 |
pingidentity | pingid_adapter_for_pingfederate | 𝑥 < 2.13.2 |
pingidentity | pingid_integration_kit | 𝑥 < 2.24 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-780 - Use of RSA Algorithm without OAEPThe software uses the RSA algorithm but does not incorporate Optimal Asymmetric Encryption Padding (OAEP), which might weaken the encryption.
- CWE-327 - Use of a Broken or Risky Cryptographic AlgorithmThe use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information.
References