PT-2020-15013 · Zkteco · Zkbiosecurity Server+1

Joey Costoya

+4

·

Published

2020-08-14

·

Updated

2020-08-21

·

CVE-2020-17473

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ZKTeco FaceDepot 7B version 1.0.213 ZKBiosecurity Server version 1.0.0 20190723
Description The issue is related to a lack of mutual authentication, which allows an attacker to impersonate the server and obtain a long-lasting token.
Recommendations For ZKTeco FaceDepot 7B version 1.0.213, consider implementing mutual authentication to prevent server impersonation. For ZKBiosecurity Server version 1.0.0 20190723, implement mutual authentication to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-17473

Affected Products

Zkbiosecurity Server
Zkteco Facedepot 7B