A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
The product uses the RSA algorithm but does not incorporate Optimal Asymmetric Encryption Padding (OAEP), which might weaken the encryption.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pingfederate | Pingidentity | 11.1.0 (including) | 11.1.5 (including) |
Pingfederate | Pingidentity | 11.2.0 (including) | 11.2.2 (including) |
Pingid_adapter_for_pingfederate | Pingidentity | * | 2.13.2 (excluding) |
Pingid_integration_kit | Pingidentity | * | 2.24 (excluding) |