CVE-2023-33371

CRITICAL

Control ID IDSecure <4.7.26.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.

Scores

CVSS v3 9.8
EPSS 0.0085
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
assaabloy/control_id_idsecure < 4.7.26.0
Published Aug 03, 2023
Tracked Since Feb 18, 2026