PT-2024-26503 · Zkteco · Zkbio Cvsecurity

Published

2024-05-30

·

Updated

2025-06-17

·

CVE-2024-35433

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ZKTeco ZKBio CVSecurity version 6.1.1
Description The issue concerns Incorrect Access Control, where an authenticated user without the necessary permissions to manage users can still create a new admin user.
Recommendations For ZKTeco ZKBio CVSecurity version 6.1.1, consider restricting access to user management functions until a fix is available, and review current user permissions to identify any potentially unauthorized admin users.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-35433

Affected Products

Zkbio Cvsecurity