Vulnerability Description
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zkteco | Zkbiosecurity Server | 1.0.0_20190723 |
| Zkteco | Facedepot 7B Firmware | 1.0.213 |
| Zkteco | Facedepot 7B | - |
Related Weaknesses (CWE)
References
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/vulnerability/8131/zktecThird Party Advisory
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/vulnerability/8131/zktecThird Party Advisory
FAQ
What is CVE-2020-17473?
CVE-2020-17473 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.
How severe is CVE-2020-17473?
CVE-2020-17473 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-17473?
Check the references section above for vendor advisories and patch information. Affected products include: Zkteco Zkbiosecurity Server, Zkteco Facedepot 7B Firmware, Zkteco Facedepot 7B.