CVE-2024-13966: ZKTeco BioTime default password
ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13966?
CVE-2024-13966 has a high severity due to the ability of unauthenticated attackers to exploit the vulnerability and gain unauthorized access.
How do I fix CVE-2024-13966?
To fix CVE-2024-13966, users must change their default passwords from '123456' to a stronger password in the Attendance Settings under 'Self-Password'.
What are the implications of CVE-2024-13966?
The implications of CVE-2024-13966 include unauthorized access to user accounts, which could lead to data breaches and loss of sensitive information.
Who is affected by CVE-2024-13966?
Users of ZKTeco BioTime who have not changed their default passwords are affected by CVE-2024-13966.
What type of attack is CVE-2024-13966 associated with?
CVE-2024-13966 is associated with an enumeration attack that allows unauthorized login attempts using default credentials.