CVE-2023-38956: Path Traversal
Published Aug 3, 2023
·Updated
A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
Affected Software
1 affected component
ZKTeco BioAccess IVS=3.3.1
Event History
Aug 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-38956?
CVE-2023-38956 is a path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 that allows unauthenticated attackers to read arbitrary files.
2
What is the severity of CVE-2023-38956?
CVE-2023-38956 has a severity rating of 7.5 (high).
3
How can an attacker exploit CVE-2023-38956?
An attacker can exploit CVE-2023-38956 by supplying a crafted payload to perform unauthorized file reads.
4
Is authentication required to exploit CVE-2023-38956?
No, authentication is not required to exploit CVE-2023-38956.
5
Is there a fix for CVE-2023-38956?
At present, there is no known fix for CVE-2023-38956. It is recommended to update to a version that is not affected by the vulnerability when available.