CVE-2020-17474: Critical severity zkteco zkbiosecurity server vulnerability
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.020190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-17474?
CVE-2020-17474 is a token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723.
What is the severity of CVE-2020-17474?
The severity of CVE-2020-17474 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2020-17474?
ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 are affected by CVE-2020-17474.
What is the impact of CVE-2020-17474?
CVE-2020-17474 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.
How can I fix CVE-2020-17474?
To fix CVE-2020-17474, it is recommended to update ZKTeco FaceDepot 7B and ZKBiosecurity Server to the latest version.