Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hc9r-5jfv-rh42

Опубликовано: 03 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.

A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.

EPSS

Процентиль: 23%
0.00075
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 6.6
nvd
почти 4 года назад

A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.

EPSS

Процентиль: 23%
0.00075
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-330