CVE-2023-3940

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published May 21, 2024
CWE ID 23

Summary

CVE-2023-3940 is a critical vulnerability affecting ZkTeco-based OEM devices, including the ProFace X, Smartec ST-FR043, and ST-FR041ME models. This Relative Path Traversal issue allows attackers to gain unauthorized access to any file on the system, potentially resulting in sensitive data exposure or system compromise. The affected devices utilize the ZAM170-NF-1.8.25-7354-Ver1.0.0 firmware, with other versions possibly being vulnerable as well.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share