CVE-2023-38951: Path Traversal
A path traversal vulnerability in ZKTeco BioTime v8.5.5 allows attackers to write arbitrary files via using a malicious SFTP configuration.
Other sources
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ZKTeco BioTimeto a version that resolves this vulnerability.Fixed in 9.0.1 (20240617.19506) - Upgrade
Upgrade
ZKTeco BioTimeto a version that resolves this vulnerability.Fixed in 9.0.1 (20240617.19506)Patch 20240617.19506 - Compensating control
Restrict access to the /base/sftpsetting/ endpoints so only authorized, trusted authenticated users can reach them (mitigates exploitation via crafted requests abusing the Username and SSH Key fields).
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-38951.
What is the severity of CVE-2023-38951?
The severity of CVE-2023-38951 is critical, with a severity value of 9.8.
What software is affected by CVE-2023-38951?
The software affected by CVE-2023-38951 is ZKTeco BioTime version 8.5.5.
How can attackers exploit CVE-2023-38951?
Attackers can exploit CVE-2023-38951 by using a malicious SFTP configuration to write arbitrary files.
Are there any references for CVE-2023-38951?
Yes, you can find references for CVE-2023-38951 at the following URLs: [http://zkteco.com](http://zkteco.com) and [https://claroty.com/team82/disclosure-dashboard/cve-2023-38951](https://claroty.com/team82/disclosure-dashboard/cve-2023-38951).