An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an administrative user.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://tenable.com/security/research/tra-2023-36 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: tenable
Published: 2023-11-27T16:34:50.656Z
Updated: 2024-08-02T08:28:21.191Z
Reserved: 2023-11-27T16:18:25.451Z
Link: CVE-2023-6329

No data.

Status : Modified
Published: 2023-11-27T17:15:09.860
Modified: 2024-11-21T08:43:38.127
Link: CVE-2023-6329

No data.