PT-2024-4480 · Zkteco+1 · Zkteco Proface X+2

Georgy Kiguradze

·

Published

2024-05-21

·

Updated

2024-06-14

·

CVE-2023-3941

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZkTeco ProFace X versions prior to the fixed version Smartec ST-FR043 versions prior to the fixed version Smartec ST-FR041ME versions prior to the fixed version ZkTeco-based OEM devices versions prior to the fixed version, including those with ZAM170-NF-1.8.25-7354-Ver1.0.0
Description The issue is related to a Relative Path Traversal vulnerability in the Handler for User Photo Upload Command and Handler for Picture Upload Command components of ZkTeco-based OEM devices. This vulnerability can be exploited by an attacker to write any file on the system with root privileges, potentially allowing them to elevate their privileges and gain access to read, modify, or delete data. The vulnerability affects devices used in high-security sectors, including nuclear plants, hospitals, and offices, which support advanced authentication methods such as facial recognition and QR-code scanning.
Recommendations For ZkTeco ProFace X, update to a version that includes a fix for this issue. For Smartec ST-FR043, update to a version that includes a fix for this issue. For Smartec ST-FR041ME, update to a version that includes a fix for this issue. For ZkTeco-based OEM devices, update to a version that includes a fix for this issue, including those with ZAM170-NF-1.8.25-7354-Ver1.0.0. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available.

Fix

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04983
CVE-2023-3941

Affected Products

Smartec St-Fr041Me
Smartec St-Fr043
Zkteco Proface X