CVE-2017-14680: Infoleak
Published Sep 21, 2017
·Updated
ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.
Affected Software
1 affected component
ZKTeco ZKTime Web=2.0.1.12280
Event History
Sep 21, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14680?
CVE-2017-14680 is rated as having a medium severity due to its potential to expose sensitive employee metadata.
2
How do I fix CVE-2017-14680?
To remedy CVE-2017-14680, implement access controls to restrict direct requests for PDF documents within ZKTime Web 2.0.1.12280.
3
What kind of data can be obtained through CVE-2017-14680?
CVE-2017-14680 allows remote attackers to obtain sensitive employee metadata such as personal information through unauthorized PDF document access.
4
Which version of ZKTime Web is affected by CVE-2017-14680?
CVE-2017-14680 affects ZKTeco ZKTime Web version 2.0.1.12280.
5
Is CVE-2017-14680 a remote or local vulnerability?
CVE-2017-14680 is a remote vulnerability that can be exploited by attackers over the internet.