CVE-2023-38950: ZKTeco BioTime Path Traversal Vulnerability
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
Other sources
ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ZKTeco BioTimeto a version that resolves this vulnerability.Fixed in 9.0.120240617.19506
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2023-38950.
What is the title of this vulnerability?
The title of this vulnerability is 'A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.'
What is the severity of CVE-2023-38950?
The severity of CVE-2023-38950 is high, with a CVSS score of 7.5.
What software version is affected by CVE-2023-38950?
The affected software version is ZKTeco BioTime v8.5.5.
How can I fix the vulnerability in ZKTeco BioTime v8.5.5?
To fix the vulnerability in ZKTeco BioTime v8.5.5, it is recommended to update to the latest version provided by the vendor.