CVE Vulnerabilities

CVE-2022-40722

Use of RSA Algorithm without OAEP

Published: Apr 25, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.

Weakness

The product uses the RSA algorithm but does not incorporate Optimal Asymmetric Encryption Padding (OAEP), which might weaken the encryption.

Affected Software

Name Vendor Start Version End Version
Pingfederate Pingidentity 11.1.0 (including) 11.1.5 (including)
Pingfederate Pingidentity 11.2.0 (including) 11.2.2 (including)
Pingid_adapter_for_pingfederate Pingidentity * 2.13.2 (excluding)
Pingid_integration_kit Pingidentity * 2.24 (excluding)

References