7.5
CVSSv3

CVE-2023-38952

Published: 03/08/2023 Updated: 08/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Insecure access control in ZKTeco BioTime v8.5.5 allows unauthenticated malicious users to read sensitive backup files and access sensitive information such as user credentials via sending a crafted HTTP request to the static files resources of the system.

Vulnerable Product Search on Vulmon Subscribe to Product

zkteco biotime 8.5.5

Exploits

BioTime versions 855 and 901 suffer from directory traversal and file write vulnerabilities This exploit also achieves remote code execution on version 855 ...