ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Assaabloy
Assaabloy control Id Idsecure |
|
CPEs | cpe:2.3:a:assaabloy:control_id_idsecure:*:*:*:*:on-premises:*:*:* | |
Vendors & Products |
Assaabloy
Assaabloy control Id Idsecure |
Fri, 27 Jun 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a Server-Side Request Forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers. | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers. |
Metrics |
cvssV3_1
|
Tue, 24 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 24 Jun 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a Server-Side Request Forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers. | |
Title | Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premises | |
Weaknesses | CWE-918 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-06-24T19:19:42.160Z
Updated: 2025-06-27T17:14:33.313Z
Reserved: 2025-06-11T15:48:15.494Z
Link: CVE-2025-49852

Updated: 2025-06-24T19:33:39.534Z

Status : Analyzed
Published: 2025-06-24T20:15:25.727
Modified: 2025-07-02T16:33:10.653
Link: CVE-2025-49852

No data.