Control iD iDSecure Multiple Denial of Service Vulnerabilities

High

Synopsis

Control iD iDSecure is an on-premises access control and time attendance management application for Windows. Version 4.8.1.0 is affected by multiple vulnerabilities:

Unauthenticated Service Restart Denial of Service (High): The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly to hold the service in a continuous restart cycle, rendering it unavailable.

Unauthenticated Uncaught Exception Denial of Service (High): The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.
 

Solution

Upgrade to Control iD iDSecure On-premises version 4.8.3.0 or later. Control iD has indicated that iDSecure is being phased out and is no longer actively promoted.

Disclosure Timeline

May 4, 2026 - Tenable sends a request for contact.
May 4, 2026 - Control iD confirms contact information.
May 27, 2026 - Tenable sends the disclosure email.
June 17, 2026 - Tenable requests acknowledgement.
June 17, 2026 - Control iD replies that they will address the issues and that iDSecure is being phased out.
June 17, 2026 - Tenable inquires whether there is a targeted release date.
July 20, 2026 - Tenable asks whether there is an update on the release and reminds Control iD of the upcoming publication date.
July 20, 2026 - Control iD replies that the fix has been published and notes that they do not actively promote the software.
July 20, 2026 - Tenable asks for the fix version and any CVE identifiers related to the fix.
July 20, 2026 - Control iD responds with the fix version and indicates that they did not reserve CVE identifiers because the software is no longer promoted.
August 3, 2026 - Tenable verifies that the issues are no longer reproducible in version 4.8.2.0.

All information within TRA advisories is provided “as is”, without warranty of any kind, including the implied warranties of merchantability and fitness for a particular purpose, and with no guarantee of completeness, accuracy, or timeliness. Individuals and organizations are responsible for assessing the impact of any actual or potential security vulnerability.

Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers. Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order.

For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page.

If you have questions or corrections about this advisory, please email [email protected]