Search Results (7 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-49851 1 Assaabloy 1 Control Id Idsecure 2025-07-02 9.8 Critical
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product.
CVE-2025-49852 1 Assaabloy 1 Control Id Idsecure 2025-07-02 7.5 High
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers.
CVE-2025-49853 1 Assaabloy 1 Control Id Idsecure 2025-07-02 9.1 Critical
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries.
CVE-2023-33371 1 Assaabloy 1 Control Id Idsecure 2024-11-21 9.8 Critical
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
CVE-2023-33370 1 Assaabloy 1 Control Id Idsecure 2024-11-21 7.5 High
An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDSecure to fault and crash, causing a denial of service.
CVE-2023-33369 1 Assaabloy 1 Control Id Idsecure 2024-11-21 9.1 Critical
A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem, causing a denial of service.
CVE-2023-33368 1 Assaabloy 1 Control Id Idsecure 2024-11-21 6.5 Medium
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.