Home/Product/assaabloy control id idsecure
Product

assaabloy control id idsecure

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-49853
< 4.7.50.0
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak
9.1CRITICAL
CVE-2025-49852
< 4.7.50.0
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which cou
7.5HIGH
CVE-2025-49851
< 4.7.50.0
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could
9.8CRITICAL
CVE-2023-6329
all versions
An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a
9.8CRITICAL
CVE-2023-33367
<= 4.7.26.0
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP fi
9.8CRITICAL
CVE-2023-33371
<= 4.7.26.0
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing
9.8CRITICAL
CVE-2023-33370
<= 4.7.26.0
An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web ser
7.5HIGH
CVE-2023-33369
<= 4.7.26.0
A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on I
9.1CRITICAL
CVE-2023-33368
<= 4.7.26.0
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users access
6.5MEDIUM
CVE-2023-2044
all versions
A vulnerability has been found in Control iD iDSecure 4.7.29.1 and classified as problematic. This vulnerability affects unknown c
3.5LOW
threatengine.sh