CVE-2022-40722
Misconfiguration of RSA padding for offline MFA in the PingID Adapter for PingFederate.
Severity Score
5.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
*Credits:
Ping Identity credits The Commonwealth Bank of Australia for the discovery of this vulnerability.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-09-14 CVE Reserved
- 2023-04-25 CVE Published
- 2024-08-03 CVE Updated
- 2024-11-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
- CWE-780: Use of RSA Algorithm without OAEP
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://docs.pingidentity.com/r/en-us/pingid/pingid_adapter_configuring_offline_mfa | Product | |
https://docs.pingidentity.com/r/en-us/pingid/pingid_integration_kit_2_20_rn | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pingidentity Search vendor "Pingidentity" | Pingfederate Search vendor "Pingidentity" for product "Pingfederate" | >= 11.1.0 <= 11.1.5 Search vendor "Pingidentity" for product "Pingfederate" and version " >= 11.1.0 <= 11.1.5" | - |
Affected
| ||||||
Pingidentity Search vendor "Pingidentity" | Pingfederate Search vendor "Pingidentity" for product "Pingfederate" | >= 11.2.0 <= 11.2.2 Search vendor "Pingidentity" for product "Pingfederate" and version " >= 11.2.0 <= 11.2.2" | - |
Affected
| ||||||
Pingidentity Search vendor "Pingidentity" | Pingid Adapter For Pingfederate Search vendor "Pingidentity" for product "Pingid Adapter For Pingfederate" | < 2.13.2 Search vendor "Pingidentity" for product "Pingid Adapter For Pingfederate" and version " < 2.13.2" | - |
Affected
| ||||||
Pingidentity Search vendor "Pingidentity" | Pingid Integration Kit Search vendor "Pingidentity" for product "Pingid Integration Kit" | < 2.24 Search vendor "Pingidentity" for product "Pingid Integration Kit" and version " < 2.24" | - |
Affected
|