CVE-2024-35431: High severity zkteco zkbio cvsecurity vulnerability
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35431?
CVE-2024-35431 has been classified as a high severity vulnerability due to its potential for unauthenticated remote file access.
How do I fix CVE-2024-35431?
To fix CVE-2024-35431, update ZKTeco ZKBio CVSecurity to version 6.4.1 or later, ensuring the application is not accessible by unauthenticated users.
Who is affected by CVE-2024-35431?
CVE-2024-35431 affects ZKTeco ZKBio CVSecurity versions up to and including 6.4.1, with potential impacts on all users of these versions.
What type of attack does CVE-2024-35431 facilitate?
CVE-2024-35431 facilitates a Directory Traversal attack, allowing unauthorized users to access and download sensitive files from the server.
Is authentication required to exploit CVE-2024-35431?
No, CVE-2024-35431 can be exploited by unauthenticated users, making it particularly dangerous.