Empowerid develops an identity and access management platform that, while narrowly scoped, operates in a security-sensitive domain where authentication and data integrity are foundational. The vulnerability profile centers on its core platform product and recurs through weakness classes including exposure of sensitive information, improper authentication, and insufficient verification of data authenticity, reflecting the access-control and trust-establishment demands inherent to identity systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Empowerid over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40260CRITICAL EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) is known, because the first fac | Aug 11, 2023 | 9.1 | 26 | NO | NO |
CVE-2023-4177MEDIUM A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknown processing of the component Multi-Factor Authentication Co | Aug 6, 2023 | 5.7 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Empowerid.
Media articles that mention a CVE ID that affects a product developed by Empowerid — matched by CVE ID, not by vendor name.