PT-2024-26503 · Zkteco · Zkbio Cvsecurity
Published
2024-05-30
·
Updated
2025-06-17
·
CVE-2024-35433
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ZKTeco ZKBio CVSecurity version 6.1.1
Description
The issue concerns Incorrect Access Control, where an authenticated user without the necessary permissions to manage users can still create a new admin user.
Recommendations
For ZKTeco ZKBio CVSecurity version 6.1.1, consider restricting access to user management functions until a fix is available, and review current user permissions to identify any potentially unauthorized admin users.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zkbio Cvsecurity