CVE-2023-6329: Control iD iDSecure passwordCustom Authentication Bypass
Published Nov 27, 2023
·Updated
An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an administrative user.
Affected Software
1 affected component
Controlid Idsecure=4.7.32.0
Event History
Nov 27, 2023
CVE Published
04:34 PM
Data Sourced
04:34 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-6329.
2
What is the title of this vulnerability?
The title of this vulnerability is Control iD iDSecure passwordCustom Authentication Bypass.
3
What is the severity of CVE-2023-6329?
The severity of CVE-2023-6329 is critical.
4
Which software version is affected by this vulnerability?
Control iD iDSecure version 4.7.32.0 is affected by this vulnerability.
5
Is there a fix available for this vulnerability?
Yes, you can refer to the vendor's website or contact them for a fix for this vulnerability.