CVE-2021-42001

Publication date

2022-04-30 21:15:24

Family

Ping Identity

State

PUBLISHED

Description

PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.