7.5
CVSSv2

CVE-2020-17474

Published: 14/08/2020 Updated: 21/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an malicious user to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zkteco zkbiosecurity server 1.0.0_20190723

zkteco facedepot_7b_firmware 1.0.213