CVE-2022-40722CWE-780

Misconfiguration of RSA padding for offline MFA in the PingID Adapter for PingFederate.

High · published April 25, 2023

CVSS v3.1
7.7
EPSS
0%
Percentile
25.5
In the wild
Unconfirmed
What it is

A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.

The record
Technical detail
CVSS v3.1
7.7 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00328 · 25.5th percentile
Weakness
CWE-780 · Use of RSA Algorithm without OAEP
Published
2023-04-25T00:00Z
EPSS history
Timeline
  • 25 APR 00:00Z
    Misconfiguration of RSA padding for offline MFA in the PingID Adapter for PingFederate.
    cvelistv5