CVE-2021-42001
—CVSS 3.1
9.9 critical
EPSS
<1%p41
Published
()
Modified
Description
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.
- Vendors
- pingidentity
- Products
- pingid desktop
- Weakness
- CWE-310
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.