9.8
CVSSv3

CVE-2023-33371

Published: 03/08/2023 Updated: 05/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing malicious users to sign arbitrary session tokens and bypass authentication.

Vulnerable Product Search on Vulmon Subscribe to Product

assaabloy control id idsecure