CVE Vulnerabilities

CVE-2022-40722

Use of RSA Algorithm without OAEP

Published: Apr 25, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.

Weakness

The product uses the RSA algorithm but does not incorporate Optimal Asymmetric Encryption Padding (OAEP), which might weaken the encryption.

Affected Software

NameVendorStart VersionEnd Version
PingfederatePingidentity11.1.0 (including)11.1.5 (including)
PingfederatePingidentity11.2.0 (including)11.2.2 (including)
Pingid_adapter_for_pingfederatePingidentity*2.13.2 (excluding)
Pingid_integration_kitPingidentity*2.24 (excluding)

References