CVE-2024-11049: ZKTeco ZKBio Time Image File photo direct request
A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /authfiles/photo/ of the component Image File Handler. The manipulation leads to direct request. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11049?
CVE-2024-11049 is classified as problematic, indicating a significant potential impact.
How do I fix CVE-2024-11049?
To address CVE-2024-11049, it is advisable to apply any patches provided by ZKTeco for version 9.0.1.
What are the impacts of CVE-2024-11049?
CVE-2024-11049 allows for remote attacks through direct requests to an image file handler.
Which software versions are affected by CVE-2024-11049?
CVE-2024-11049 affects ZKTeco ZKBio Time version 9.0.1.
Can CVE-2024-11049 be exploited remotely?
Yes, CVE-2024-11049 can be exploited remotely due to its nature.