CVE-2023-3940: Multiple arbitrary file reads in ZkTeco-based OEM devices
Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to access any file on the system.
This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0 and possibly others.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3940?
CVE-2023-3940 is identified as a critical vulnerability due to its potential for unauthorized access to system files.
How do I fix CVE-2023-3940?
To fix CVE-2023-3940, administrators should update their ZkTeco-based devices to the latest firmware that addresses the relative path traversal issue.
Which devices are affected by CVE-2023-3940?
CVE-2023-3940 affects ZkTeco-based OEM devices, including the ZkTeco ProFace X and Smartec ST-FR043 and ST-FR041ME.
What type of vulnerability is CVE-2023-3940?
CVE-2023-3940 is a relative path traversal vulnerability allowing attackers to access arbitrary files on the affected devices.
What are the risks associated with CVE-2023-3940?
The risks of CVE-2023-3940 include potential exposure of sensitive information and unauthorized manipulation of device files.