PT-2022-26677 · Zkteco · Zmm200+9

Published

2022-12-25

·

Updated

2023-08-08

·

CVE-2022-42953

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZKTeco ZEM500-510-560-760 versions prior to 8.88 ZKTeco ZEM600-800 versions prior to 8.88 ZKTeco ZEM720 versions prior to 8.88 ZKTeco ZMM200-220-210 versions prior to 15.00
Description Certain ZKTeco products allow access to sensitive information via direct requests for the "form/DataApp?style=1" and "form/DataApp?style=0" URLs.
Recommendations For ZKTeco ZEM500-510-560-760 versions prior to 8.88, update to firmware version 8.88. For ZKTeco ZEM600-800 versions prior to 8.88, update to firmware version 8.88. For ZKTeco ZEM720 versions prior to 8.88, update to firmware version 8.88. For ZKTeco ZMM200-220-210 versions prior to 15.00, update to firmware version 15.00.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-42953

Affected Products

Zem500
Zem510
Zem560
Zem600
Zem720
Zem760
Zem800
Zmm200
Zmm210
Zmm220