CVE-2021-41995: PingID Mac Login prior to 1.1 vulnerable to pre-computed dictionary attacks
Published Jun 30, 2022
·Updated
A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
Affected Software
2 affected components
pingidentity Pingid Integration For Mac Login<1.1
Apple macOS
Event History
Jun 30, 2022
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-41995.
2
What is the severity of CVE-2021-41995?
The severity of CVE-2021-41995 is high with a CVSS score of 7.5.
3
What is the impact of CVE-2021-41995?
CVE-2021-41995 allows for pre-computed dictionary attacks, leading to an offline multi-factor authentication bypass.
4
How can I fix CVE-2021-41995?
To fix CVE-2021-41995, it is recommended to update to PingID Mac Login version 1.1 or later.
5
Where can I find more information about CVE-2021-41995?
You can find more information about CVE-2021-41995 in the official documentation from PingIdentity and the PingID downloads page.