CVE-2023-33371: Critical severity assaabloy control id idsecure vulnerability
Published Aug 3, 2023
·Updated
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
Affected Software
1 affected component
Assaabloy Control Id Idsecure<=4.7.26.0
Event History
Aug 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-33371.
2
What is the severity of CVE-2023-33371?
The severity of CVE-2023-33371 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is Control ID IDSecure version 4.7.26.0 and prior.
4
What is the impact of this vulnerability?
This vulnerability allows attackers to sign arbitrary session tokens and bypass authentication.
5
Is there a fix available for this vulnerability?
A fix for this vulnerability is not mentioned in the provided information.