← Back

CVE-2021-41993

nvd nist
Published: Apr 30, 2022Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Exploitability: 0.4 / Impact: 4.0
Source: NVD

Description

A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.

Affected (2)

2 products
Pingid
Pingid Windows Login
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.19
All versions

References (4)

Source: responsible-disclosure@pingidentity.com
PatchRelease NotesVendor Advisory
Source: responsible-disclosure@pingidentity.com
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.