# CVE-2022-40722

## Summary

- **CVE ID:** CVE-2022-40722
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N)
- **CWE:** CWE-780
- **Published:** Apr 25, 2023
- **Last Modified:** Mar 13, 2026

## Description

A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.

## Affected Products

- Ping Identity — PingID Adapter for PingFederate (2.13.2)
- Ping Identity — PingID Integration Kit (includes PingID Adapter) (2.24)
- Ping Identity — PingFederate (includes PingID Adapter) (11.1.0)
- Ping Identity — PingFederate (includes PingID Adapter) (11.1.5)
- Ping Identity — PingFederate (includes PingID Adapter) (11.2.0)
- Ping Identity — PingFederate (includes PingID Adapter) (11.2.2)

## References

- [CNA](https://docs.pingidentity.com/r/en-us/pingid/pingid_integration_kit_2_20_rn)
- [CNA](https://docs.pingidentity.com/r/en-us/pingid/pingid_adapter_configuring_offline_mfa)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.01%
- **EPSS Percentile:** 0.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._