CVE-2021-41993: PingID Android mobile application prior to 1.19 vulnerable to pre-computed dictionary attacks
Published Apr 30, 2022
·Updated
A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
Affected Software
2 affected components
pingidentity Pingid Android<1.19
pingidentity Pingid Windows Login
Remediation
Event History
Apr 30, 2022
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this misconfiguration in the PingID Android app?
The vulnerability ID for this misconfiguration in the PingID Android app is CVE-2021-41993.
2
What type of vulnerability is this?
This vulnerability is a misconfiguration vulnerability.
3
What is the severity of CVE-2021-41993?
The severity of CVE-2021-41993 is medium with a CVSS score of 4.8.
4
What is the affected software for CVE-2021-41993?
The affected software for CVE-2021-41993 is the PingID Android app prior to version 1.19 and PingID Windows Login.
5
How can the misconfiguration in the PingID Android app be exploited?
The misconfiguration in the PingID Android app can be exploited through pre-computed dictionary attacks, resulting in an offline MFA bypass when using PingID Windows Login.