CVE-2021-39434: High severity zkteco zktime web vulnerability
Published Dec 5, 2022
·Updated
A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.
Affected Software
8 affected components
ZKTeco ZKTime>=10.0<=11.1.0
ZKTeco ZKTime=11.1.0
ZKTeco ZKTime=11.1.0-20180901
ZKTeco ZKTime=11.1.0-20190510.1
ZKTeco ZKTime=11.1.0-20200309.3
ZKTeco ZKTime=11.1.0-20200930
ZKTeco ZKTime=11.1.0-20201231
ZKTeco ZKTime=11.1.0-20210220
Event History
Dec 5, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Dec 6, 2022
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-39434.
2
What is the severity of CVE-2021-39434?
The severity of CVE-2021-39434 is high with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2021-39434?
ZKTeco ZKTime versions 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220 are affected.
4
What is the CVE description of CVE-2021-39434?
CVE-2021-39434 is a vulnerability in ZKTeco ZKTime that allows unauthorized access through a default username and password for an administrator account.
5
Is there a fix available for CVE-2021-39434?
There is currently no official fix available for CVE-2021-39434. It is recommended to change the default administrator credentials.