PT-2024-14055 · Zkteco · Zkteco Biotime

Abdullah Alqannam

·

Published

2024-03-21

·

Updated

2024-08-16

·

CVE-2023-51141

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZKTeko BioTime versions 8.5.4 and earlier
Description An issue in the Authentication & Authorization component allows a remote attacker to obtain sensitive information. Monitor access logs for unusual activity.
Recommendations For ZKTeko BioTime versions 8.5.4 and earlier, update the software immediately to resolve the issue. As a temporary workaround, consider restricting access to the Authentication & Authorization component until a patch is available.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2023-51141

Affected Products

Zkteco Biotime