VulnerabilityModified
CVE-2023-33368
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.
MEDIUM 6.5EPSS 0.55%
Does this matter?
Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.
Description
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-668
- Affected
- assaabloy/control id idsecure
- Source
- cve@mitre.org
References
- https://claroty.com/team82/disclosure-dashboard/cve-2023-33368Third Party Advisory
- https://www.controlid.com.br/en/access-control/idsecure/Vendor Advisory
- https://claroty.com/team82/disclosure-dashboard/cve-2023-33368Third Party Advisory
- https://www.controlid.com.br/en/access-control/idsecure/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.