CVE-2023-38950

unknown KEV
Published 2025-05-19 · Modified 2025-05-19
CVSS v3
CVSS v2
VIR risk
1.5

Description

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.

CISA KEV

Vendor
ZKTeco
Product
BioTime
Due date
2025-06-09

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://www.zkteco.com/en/Security_Bulletinsibs ; https://nvd.nist.gov/vuln/detail/CVE-2023-38950

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.