PT-2024-4718 · Zkteco+1 · Zkteco Proface X+2
Alexander Zaytsev
·
Published
2024-05-21
·
Updated
2024-05-21
·
CVE-2023-3938
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
ZkTeco ProFace X versions with firmware ZAM170-NF-1.8.25
Smartec ST-FR043 versions with firmware ZAM170-NF-1.8.25
Smartec ST-FR041ME versions with firmware ZAM170-NF-1.8.25
Description:
The issue is related to improper neutralization of special elements used in an SQL command, which can allow an attacker to execute arbitrary SQL code, bypass security restrictions, and gain unauthorized access to protected information. This can enable an attacker to authenticate as any user from the device database.
Recommendations:
For ZkTeco ProFace X with firmware ZAM170-NF-1.8.25, update the firmware to a version that addresses the SQL Injection vulnerability.
For Smartec ST-FR043 with firmware ZAM170-NF-1.8.25, update the firmware to a version that addresses the SQL Injection vulnerability.
For Smartec ST-FR041ME with firmware ZAM170-NF-1.8.25, update the firmware to a version that addresses the SQL Injection vulnerability.
As a temporary workaround, consider restricting access to the device database to minimize the risk of exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smartec St-Fr041Me
Smartec St-Fr043
Zkteco Proface X