Vulnerability Description
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zkteco | Biotime | 8.5.5 |
Related Weaknesses (CWE)
References
- https://claroty.com/team82/disclosure-dashboard/cve-2023-38951Third Party Advisory
- https://github.com/omair2084/biotime-rce-8.5.5/blob/main/biotime_enum.py
- https://krashconsulting.com/fury-of-fingers-biotime-rce/
- https://www.zkteco.com/en/ZKBio_Time/ZKBioTime#Download
- https://www.zkteco.com/en/announcement
- http://zkteco.comProduct
- https://claroty.com/team82/disclosure-dashboard/cve-2023-38951Third Party Advisory
- https://sploitus.com/exploit?id=PACKETSTORM:177859
FAQ
What is CVE-2023-38951?
CVE-2023-38951 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints ...
How severe is CVE-2023-38951?
CVE-2023-38951 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-38951?
Check the references section above for vendor advisories and patch information. Affected products include: Zkteco Biotime.