PingID Desktop PIN attempt lockout bypass.
CVE-2022-40725
7.3HIGH
What is CVE-2022-40725?
PingID Desktop prior to version 1.7.4 contains a vulnerability that allows attackers to bypass the maximum allowed PIN attempts. This exploitation can prevent the time-based lockout mechanism from triggering, potentially allowing unauthorized users to gain access to sensitive accounts. Organizations should ensure they are using the latest version of PingID Desktop to mitigate this risk.
Affected Version(s)
PingID Desktop for macOS 1.7.4
PingID Desktop for Windows 1.7.4