CVE-2023-38951
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Aug 3, 2023
Updated: Aug 8, 2023
CWE ID 22
Summary
CVE-2023-38951 is a recently disclosed vulnerability affecting ZKTeco BioTime version 8.5.5. This issue permits attackers to manipulate the SFTP configuration and traverse paths beyond intended limits, resulting in the unintended creation or modification of arbitrary files on the affected system. Successful exploitation could lead to serious security implications, including unauthorized access or data leakage. Systems running this version of ZKTeco BioTime should be updated promptly to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- ZKTeco Co., Ltd.