9.9
CVE-2021-42001
- EPSS 0.22%
- Veröffentlicht 30.04.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:27:03
- Quelle responsible-disclosure@pingide
- CVE-Watchlists
- Unerledigt
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pingidentity ≫ Pingid Desktop SwPlatformmac_os_x Version < 1.7.3
Pingidentity ≫ Pingid Desktop SwPlatformwindows Version < 1.7.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.444 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.9 | 3.1 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
| responsible-disclosure@pingidentity.com | 8 | 1.3 | 6 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
|