CVE-2024-35433: High severity zkteco zkbio cvsecurity vulnerability
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35433?
CVE-2024-35433 has been classified as a critical severity vulnerability due to the potential for unauthorized administrative access.
How do I fix CVE-2024-35433?
To fix CVE-2024-35433, update ZKTeco ZKBio CVSecurity to the latest version that addresses this access control vulnerability.
Who is affected by CVE-2024-35433?
CVE-2024-35433 affects authenticated users of ZKTeco ZKBio CVSecurity 6.1.1 who do not have the permissions to manage users.
What is the exploit mechanism for CVE-2024-35433?
The exploit mechanism for CVE-2024-35433 allows an authenticated user to create a new admin user without having sufficient permissions.
Can CVE-2024-35433 be exploited remotely?
CVE-2024-35433 requires an authenticated user to exploit the vulnerability, making it less likely to be executed remotely without prior access.