CVE-2023-38950
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
An unauthenticated attacker can read any file on a ZKTeco BioTime server by sending a specially crafted request to the iclock API. This allows access to sensitive data like configuration files and credentials without needing to log in.
Path traversal vulnerability in ZKTeco BioTime v8.5.5 iclock API allows unauthenticated remote attackers to read arbitrary files via malformed path parameters. The vulnerability exploits insufficient input validation on file path handling, enabling directory traversal sequences to bypass access controls and retrieve sensitive system files.
The full analysis of this CVE is available in Portuguese →