VendorsASSA ABLOYcontrol_id_idsecureany version
Vulnerabilities

ASSA ABLOY Control iD iDSecure any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2023-33367
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution.
Published 2023-08-05 · Modified
9.8EPSS 0.011
CVE-2023-33371
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
Published 2023-08-03 · Modified
9.8EPSS 0.009
CVE-2025-49851
Improper Authentication in ControlID iDSecure On-premises
Published 2025-06-24 · Analyzed
9.8EPSS 0.005
CVE-2025-49853
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID iDSecure On-premises
Published 2025-06-24 · Analyzed
9.3EPSS 0.005
CVE-2023-33369
A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem, causing a denial of service.
Published 2023-08-03 · Modified
9.1EPSS 0.007
CVE-2025-49852
Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premises
Published 2025-06-24 · Analyzed
8.7EPSS 0.004
CVE-2023-33370
An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDSecure to fault and crash, causing a denial of service.
Published 2023-08-03 · Modified
7.5EPSS 0.006
CVE-2023-33368
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.
Published 2023-08-03 · Modified
6.5EPSS 0.005