CVE-2021-41993

MEDIUM

PingID Android <1.19 - Info Disclosure

Title source: llm
STIX 2.1

Description

A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.

Scores

CVSS v3 6.6
EPSS 0.0008
EPSS Percentile 22.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-310 CWE-330
Status published
Products (2)
pingidentity/pingid < 1.19
pingidentity/pingid_windows_login
Published Apr 30, 2022
Tracked Since Feb 18, 2026