Controlid maintains a focused portfolio of identity and access control products, including its RHID and IDSecure offerings, which serve authentication and session-management functions in enterprise environments. The durable signal in its vulnerability profile centers on web-application input handling and authentication logic, with recurring issues in direct request vulnerabilities, improper authentication mechanisms, and cross-site scripting flaws characteristic of access-control and identity-management systems.
The number and severity of CVEs published that impact products developed by Controlid over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6329CRITICAL An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthentic | Nov 27, 2023 | 9.8 | 79 | NO | YES |
CVE-2023-2524CRITICAL A vulnerability classified as critical has been found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/#/. The manipulation leads to direct request. It is | May 4, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-2421MEDIUM A vulnerability classified as problematic has been found in Control iD RHiD 23.3.19.0. Affected is an unknown function of the file /v2/#/add/department. The manipulation of the arg | Apr 29, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Controlid.
Media articles that mention a CVE ID that affects a product developed by Controlid — matched by CVE ID, not by vendor name.