CVE-2023-38949: High severity Zkteco BioTime vulnerability
Published Aug 3, 2023
·Updated
An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.
Affected Software
1 affected component
Zkteco BioTime=8.5.5
Event History
Aug 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
11:15 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the issue in ZKTeco BioTime v8.5.5?
The vulnerability ID for the issue in ZKTeco BioTime v8.5.5 is CVE-2023-38949.
2
What is the severity level of CVE-2023-38949?
The severity level of CVE-2023-38949 is high with a score of 7.5.
3
How can an attacker exploit CVE-2023-38949?
Unauthenticated attackers can exploit CVE-2023-38949 by sending a crafted web request to reset the Administrator password.
4
What software versions are affected by CVE-2023-38949?
CVE-2023-38949 affects ZKTeco BioTime version 8.5.5.
5
Is authentication required to exploit CVE-2023-38949?
No, authentication is not required to exploit CVE-2023-38949.