First published: Thu Jun 30 2022(Updated: )
A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Pingid Integration For Mac Login | <1.1 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-41995.
The severity of CVE-2021-41995 is high with a CVSS score of 7.5.
CVE-2021-41995 allows for pre-computed dictionary attacks, leading to an offline multi-factor authentication bypass.
To fix CVE-2021-41995, it is recommended to update to PingID Mac Login version 1.1 or later.
You can find more information about CVE-2021-41995 in the official documentation from PingIdentity and the PingID downloads page.