ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code Execution
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.3epss 0.8%
probabilidade de exploração
0.8%top 48% das CVEs
exploração observada
nãonenhuma fonte reporta
ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute arbitrary code with SYSTEM privileges.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
ZKTeco Inc. · ZKTeco ZKBioSecurityReferências
https://cxsecurity.com/issue/WLB-2016080266https://exchange.xforce.ibmcloud.com/vulnerabilities/116484https://packetstormsecurity.com/files/138567https://www.exploit-db.com/exploits/40324/https://www.vulncheck.com/advisories/zkteco-zkbiosecurity-hardcoded-credentials-remote-code-executionhttps://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5362.php