9.8
CVE-2023-33371
- EPSS 0.06%
- Veröffentlicht 03.08.2023 01:15:11
- Zuletzt bearbeitet 21.11.2024 08:05:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Assaabloy ≫ Control Id Idsecure Version <= 4.7.26.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.195 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.