Vulnerability record · CVE-2023-6329 · published 27 November 2023
CVE-2023-6329: Control iD iDSecure authentication bypass via passwordCustom login option
CControlid · Idsecure
Control iD iDSecure v4.7.32.0 contains an authentication bypass in the login routine of iDS-Core.dll. A "passwordCustom" option lets an unauthenticated attacker compute valid credentials and log in as an administrative user. This gives full control of the access control platform without any prior access.
Description
An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an administrative user.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, and public exploit material plus very high EPSS make this an urgent patch for any internet- or broadly reachable iDSecure deployment.
What it is
Control iD iDSecure v4.7.32.0 contains an authentication bypass in the login routine of iDS-Core.dll. A "passwordCustom" option lets an unauthenticated attacker compute valid credentials and log in as an administrative user. This gives full control of the access control platform without any prior access.
Impact
An attacker gains administrative access to iDSecure, allowing them to manage users, credentials and door or device configuration. That can translate into physical access control compromise, not just data exposure.
Attack surface
Reachable over the network via the iDSecure login interface; the CVSS vector shows no privileges and no user interaction required. Any host that can reach the login endpoint can attempt the bypass.
Exploitation
Not listed in CISA KEV, but EPSS is 0.64996 (99.2nd percentile) and the only reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.
What to do
- Upgrade iDSecure to a version later than v4.7.32.0 that fixes the authentication bypass; confirm the fixed build with Control iD.
- If patching is not immediately possible, restrict network access to the iDSecure login interface to trusted management networks only.
- Rotate administrative credentials and review accounts for unauthorized additions or changes.
- Monitor iDSecure and iDS-Core.dll logs for unexpected administrative logins, especially from unfamiliar source addresses.
Detection
- Alert on successful administrative logins to iDSecure from unexpected or external source IPs.
- Hunt for authentication attempts that use or reference the passwordCustom option in iDSecure logs or request data.
- Review iDSecure audit logs for new admin accounts, permission changes or configuration edits made outside normal change windows.
- Correlate iDSecure login events with network flow data to spot access from hosts that do not normally manage the platform.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://tenable.com/security/research/tra-2023-36 | ExploitThird Party Advisory |
| https://tenable.com/security/research/tra-2023-36 | ExploitThird Party Advisory |
Track CVE-2023-6329 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6329), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.