CVE Feed

    Dashboard / CVE / CVE-2023-38950

    CVE-2023-38950

    A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

    Published:Aug 3, 2023
    Last Modified:Nov 7, 2025
    EPS:Aug 3, 2023
    EPSS Score:0.80298
    CVSS Score:7.5

    CISA Notification

    Description

    A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

    Required Action:

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Jun 9, 2025
    459 days ago
    Alert Date
    May 19, 2025
    480 days ago

    Affected Products

    Vendor
    Zkteco
    Product
    Biotime

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High