CVE-2022-40722
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
- EPSS probability
- 0.01%
- CWE
- CWE-780
- Published
- 2023-04-25
- Last modified
- 2026-03-13
Affected products
- Ping Identity PingID Adapter for PingFederate
- Ping Identity PingID Integration Kit (includes PingID Adapter)
- Ping Identity PingFederate (includes PingID Adapter)
- Ping Identity PingFederate (includes PingID Adapter)
- Ping Identity PingFederate (includes PingID Adapter)
- Ping Identity PingFederate (includes PingID Adapter)
Weakness type
Related vulnerabilities
- CVE-2025-9071 — Insecure RSA-OAEP implementation with all-zero seed for padding in Oberon PSA Crypto
- CVE-2024-51456 — IBM Robotic Process Automation information disclosure