Vulnerability Description
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pingidentity | Pingid Desktop | < 1.7.3 |
Related Weaknesses (CWE)
References
- https://docs.pingidentity.com/bundle/pingid/page/dyt1645545885978.htmlRelease NotesVendor Advisory
- https://www.pingidentity.com/en/resources/downloads/pingid.htmlPatch
- https://docs.pingidentity.com/bundle/pingid/page/dyt1645545885978.htmlRelease NotesVendor Advisory
- https://www.pingidentity.com/en/resources/downloads/pingid.htmlPatch
FAQ
What is CVE-2021-42001?
CVE-2021-42001 is a vulnerability with a CVSS score of 8.0 (HIGH). PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successf...
How severe is CVE-2021-42001?
CVE-2021-42001 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42001?
Check the references section above for vendor advisories and patch information. Affected products include: Pingidentity Pingid Desktop.