Impact
The vulnerability allows an unauthenticated attacker to repeatedly invoke the /api/license/restartService endpoint, causing the iDSecure service process to terminate and relaunch in a continuous restart cycle. This results in the service being rendered unavailable, effectively denying legitimate users of the system's functionality. The weakness is a lack of authentication controls on a critical restart routine, classified as CWE-306.
Affected Systems
Control iD iDSecure versions prior to 4.8.3.0 are affected. No specific sub‑versions are listed beyond this cut‑off.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate‑to‑high severity, while the EPSS score of <1% suggests the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog, and the attacker requires only the ability to reach the API endpoint; no credentials or special privileges are needed. Continuous service restarts would disrupt availability, potentially impacting business operations but not compromising data confidentiality or integrity.
OpenCVE Enrichment