Controlid

Idsecure

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 16.09.2026 15:23:21
  • Zuletzt bearbeitet 18.09.2026 19:18:42

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference...

  • EPSS 0.52%
  • Veröffentlicht 16.09.2026 15:23:14
  • Zuletzt bearbeitet 18.09.2026 19:18:42

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service pr...

  • EPSS 0.46%
  • Veröffentlicht 24.06.2025 19:23:19
  • Zuletzt bearbeitet 02.07.2025 16:32:40

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries.

  • EPSS 0.37%
  • Veröffentlicht 24.06.2025 19:19:42
  • Zuletzt bearbeitet 02.07.2025 16:33:10

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers.

  • EPSS 0.5%
  • Veröffentlicht 24.06.2025 19:17:08
  • Zuletzt bearbeitet 02.07.2025 16:33:17

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an Improper Authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product.

Exploit
  • EPSS 65%
  • Veröffentlicht 27.11.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 08:43:38

An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass ...