CVE-2020-17473: Medium severity zkteco zkbiosecurity server vulnerability
Published Aug 14, 2020
·Updated
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.020190723 allows an attacker to obtain a long-lasting token by impersonating the server.
Affected Software
3 affected components
ZKTeco ZKBiosecurity Server=1.0.0_20190723
ZKTeco Facedepot 7b Firmware=1.0.213
ZKTeco FaceDepot 7B
Event History
Aug 14, 2020
CVE Published
via MITRE·07:12 PM
Data Sourced
via MITRE·07:12 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-17473.
2
What is the severity of CVE-2020-17473?
The severity of CVE-2020-17473 is medium.
3
How does CVE-2020-17473 affect ZKTeco FaceDepot 7B?
CVE-2020-17473 affects ZKTeco FaceDepot 7B by allowing an attacker to obtain a long-lasting token by impersonating the server.
4
How does CVE-2020-17473 affect ZKBiosecurity Server?
CVE-2020-17473 affects ZKBiosecurity Server by allowing an attacker to obtain a long-lasting token by impersonating the server.
5
Is ZKTeco FaceDepot 7B vulnerable to CVE-2020-17473?
Yes, ZKTeco FaceDepot 7B is vulnerable to CVE-2020-17473.
6
Is ZKBiosecurity Server vulnerable to CVE-2020-17473?
Yes, ZKBiosecurity Server is vulnerable to CVE-2020-17473.
7
How can the vulnerability be fixed?
To fix the vulnerability, it is recommended to apply the latest security patch provided by ZKTeco.