Vulnerability Description
ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zkteco | Biotime | 8.5.4 |
Related Weaknesses (CWE)
References
- https://codingkoala.eu/posts/CVE202230515/ExploitThird Party Advisory
- https://www.zkteco.me/software-5ProductVendor Advisory
- https://codingkoala.eu/posts/CVE202230515/ExploitThird Party Advisory
- https://www.zkteco.me/software-5ProductVendor Advisory
FAQ
What is CVE-2022-30515?
CVE-2022-30515 is a vulnerability with a CVSS score of 5.3 (MEDIUM). ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.
How severe is CVE-2022-30515?
CVE-2022-30515 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30515?
Check the references section above for vendor advisories and patch information. Affected products include: Zkteco Biotime.