CVE-2023-6329: Controlid Idsecure

Critical severity, CVSS 9.8. EPSS: 65% chance of exploitation in the next 30 days.

An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an administrative user.

Affected products

Published 2023-11-27. Last modified 2026-06-17.