CVE-2021-41992: PingID Windows Login RSA cryptographic weakness with possible offline MFA bypass
Published Apr 30, 2022
·Updated
A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
Affected Software
1 affected component
pingidentity Pingid Integration For Windows Login<2.7
Event History
Apr 30, 2022
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-41992?
CVE-2021-41992 is a vulnerability in PingID Windows Login prior to version 2.7 that allows for pre-computed dictionary attacks leading to an offline MFA bypass.
2
How severe is CVE-2021-41992?
CVE-2021-41992 has a severity rating of high (5.6).
3
What software is affected by CVE-2021-41992?
PingID Windows Login versions prior to 2.7 are affected by CVE-2021-41992.
4
How do I fix CVE-2021-41992?
To fix CVE-2021-41992, users should update PingID Windows Login to version 2.7 or later.
5
Where can I find more information about CVE-2021-41992?
More information about CVE-2021-41992 can be found on the Ping Identity documentation and download pages.