CVE-2023-38955: High severity ZKTeco BioAccess IVS vulnerability
Published Aug 3, 2023
·Updated
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
Affected Software
1 affected component
ZKTeco BioAccess IVS=3.3.1
Event History
Aug 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-38955.
2
What is the severity level of CVE-2023-38955?
The severity level of CVE-2023-38955 is high with a CVSS score of 7.5.
3
How can attackers exploit CVE-2023-38955?
Attackers can exploit CVE-2023-38955 to obtain sensitive information about all managed devices, including their IP addresses and device names.
4
Which version of ZKTeco BioAccess IVS is affected by CVE-2023-38955?
Version 3.3.1 of ZKTeco BioAccess IVS is affected by CVE-2023-38955.
5
Are authentication credentials required to exploit CVE-2023-38955?
No, authentication credentials are not required to exploit CVE-2023-38955.