Zkteco · Zkbiosecurity Server · CVE-2020-17474
**Name of the Vulnerable Software and Affected Versions**
ZKTeco FaceDepot 7B version 1.0.213
ZKBiosecurity Server version 1.0.0 20190723
**Description**
A token-reuse issue allows an attacker to create new users, elevate existing users to administrators, delete users, and download user faces from the database.
**Recommendations**
For ZKTeco FaceDepot 7B version 1.0.213, update to a version that fixes this issue.
For ZKBiosecurity Server version 1.0.0 20190723, update to a version that fixes this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.