An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an administrative user.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://tenable.com/security/research/tra-2023-36 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: tenable
Published: 2023-11-27T16:34:50.656Z
Updated: 2024-08-02T08:28:21.191Z
Reserved: 2023-11-27T16:18:25.451Z
Link: CVE-2023-6329
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-11-27T17:15:09.860
Modified: 2024-11-21T08:43:38.127
Link: CVE-2023-6329
Redhat
No data.