CVE-2023-2524: Control iD RHiD direct request
Published May 4, 2023
·Updated
A vulnerability classified as critical has been found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/#/. The manipulation leads to direct request. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-228015. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
1 affected component
Controlid Rhid=23.3.19.0
Event History
May 4, 2023
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
DescriptionSeverityWeakness
Data Sourced
07:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-2524?
The severity of CVE-2023-2524 is critical.
2
How can I exploit CVE-2023-2524?
CVE-2023-2524 can be exploited remotely by manipulating a specific file.
3
What software version is affected by CVE-2023-2524?
Control iD RHiD version 23.3.19.0 is affected by CVE-2023-2524.
4
Is there a fix for CVE-2023-2524?
A fix for CVE-2023-2524 may be available from the vendor. It is recommended to update to the latest version of Control iD RHiD.
5
What is the CWE ID for CVE-2023-2524?
The CWE ID for CVE-2023-2524 is CWE-425.