9.9
CVE-2021-42001
- EPSS 0.49%
- Veröffentlicht 30.04.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:27:03
- Erkennungen
PingID Desktop encryption libraries misconfiguration can lead to sensitive data exposure
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pingidentity ≫ Pingid Desktop SwPlatform mac_os_x Version < 1.7.3
Pingidentity ≫ Pingid Desktop SwPlatform windows Version < 1.7.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.386 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.9 | 3.1 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
| responsible-disclosure@pingidentity.com | 8 | 1.3 | 6 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
|
https://www.pingidentity.com/en/resources/downloads/pingid.html
https://docs.pingidentity.com/bundle/pingid/page/dyt1645545885978.html