CVE-2022-30515: Medium severity zkteco biotime vulnerability
Published Nov 8, 2022
·Updated
ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.
Affected Software
2 affected components
Zkteco BioTime=8.5.4
Zkteco BioTime=8.5.5
Event History
Nov 8, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-30515?
CVE-2022-30515 is a vulnerability in ZKTeco BioTime 8.5.4 and 8.5.5 that allows unauthorized access to employee photos through filename enumeration.
2
How severe is CVE-2022-30515?
CVE-2022-30515 has a severity score of 5.3 (Medium).
3
Which versions of ZKTeco BioTime are affected by CVE-2022-30515?
ZKTeco BioTime versions 8.5.4 and 8.5.5 are affected by CVE-2022-30515.
4
How can an attacker exploit CVE-2022-30515?
An attacker can exploit CVE-2022-30515 by performing filename enumeration on folders containing employee photos to view them without authentication.
5
Is there a fix for CVE-2022-30515?
At the time of writing, there is no known fix or patch available for CVE-2022-30515. It is recommended to follow the vendor's advisory and implement mitigations if possible.