Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qpc-pm8w-mgv5

Опубликовано: 25 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.

A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.

EPSS

Процентиль: 1%
0.00009
Низкий

7.7 High

CVSS3

Дефекты

CWE-327
CWE-780

Связанные уязвимости

CVSS3: 7.7
nvd
почти 3 года назад

A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.

EPSS

Процентиль: 1%
0.00009
Низкий

7.7 High

CVSS3

Дефекты

CWE-327
CWE-780