CVE-2024-35429: Path Traversal
Published May 30, 2024
·Updated
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.
Affected Software
1 affected component
Zkteco ZKBio CVSecurity=6.1.1
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 30, 2024
CVE Published
via NVD·05:15 PM
Aug 2, 2024
Data Sourced
via MITRE·02:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35429?
CVE-2024-35429 has been assigned a medium severity rating due to its potential for unauthorized file access.
2
How do I fix CVE-2024-35429?
To mitigate CVE-2024-35429, users should update ZKTeco ZKBio CVSecurity to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2024-35429?
CVE-2024-35429 affects version 6.1.1 of the ZKTeco ZKBio CVSecurity software.
4
What type of vulnerability is CVE-2024-35429?
CVE-2024-35429 is classified as a Directory Traversal vulnerability.
5
Can CVE-2024-35429 lead to data exposure?
Yes, CVE-2024-35429 can potentially allow attackers to access sensitive files on the server.