Impact
Control iD iDSecure allows an unauthenticated attacker to trigger a null reference exception on the /api/dguardintegration/dguardVersion endpoint. The underlying code dereferences a login state that may be unset and the function is asynchronous and returns void, so the exception is unhandled and can terminate the iDSecure process. The result is a service disruption without affecting data integrity or confidentiality.
Affected Systems
Vulnerable installations are those running Control iD iDSecure versions earlier than 4.8.3.0. The issue is tied to the iDSecure product and is specific to the identified product line.
Risk and Exploitability
The CVSS score of 7.5 indicates a high likelihood of serious impact once triggered, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog and requires no authentication to exercise, meaning any host exposed to the API can be impacted. The attack path involves sending an unauthenticated request to the mentioned endpoint, causing the unhandled exception and process termination.
OpenCVE Enrichment