CVE-2023-38950highunder attackCWE-22

CVE-2023-38950

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.5epss 92%
from disclosure to weapon
Published on NVDAug 3
CISA KEV+655d
exploitation probability
92%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2025-06-09

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

An unauthenticated attacker can read any file on a ZKTeco BioTime server by sending a specially crafted request to the iclock API. This allows access to sensitive data like configuration files and credentials without needing to log in.

Technical detail

Path traversal vulnerability in ZKTeco BioTime v8.5.5 iclock API allows unauthenticated remote attackers to read arbitrary files via malformed path parameters. The vulnerability exploits insufficient input validation on file path handling, enabling directory traversal sequences to bypass access controls and retrieve sensitive system files.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.