Control iD RHiD direct request
CVE-2023-2524

6.3MEDIUM

Key Information:

Vendor

Control Id

Status
Vendor
CVE Published:
4 May 2023

What is CVE-2023-2524?

A significant security flaw has been discovered in Control iD RHiD version 23.3.19.0, which allows attackers to leverage direct requests on the affected software. This vulnerability can be exploited remotely, posing a risk to affected systems. The issue resides in the file path /v2/#/, and despite early disclosure attempts to the vendor, there has been no response. Organizations using this version should take immediate action to mitigate potential threats.

Affected Version(s)

RHiD 23.3.19.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stux (VulDB User)
.