PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.
References
Link | Resource |
---|---|
https://docs.pingidentity.com/bundle/pingid/page/dyt1645545885978.html | Release Notes Vendor Advisory |
https://www.pingidentity.com/en/resources/downloads/pingid.html | Patch |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-04-30 15:15
Updated : 2022-09-02 20:55
NVD link : CVE-2021-42001
Mitre link : CVE-2021-42001
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
pingidentity
- pingid_desktop