Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2023-38958

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.
Attacker Value
Unknown

CVE-2023-38956

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
Attacker Value
Unknown

CVE-2023-38955

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
Attacker Value
Unknown

CVE-2023-38954

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.