Vulnerability Description
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zkteco | Bioaccess Ivs | 3.3.1 |
Related Weaknesses (CWE)
References
- http://zkteco.comNot Applicable
- https://claroty.com/team82/disclosure-dashboard/cve-2023-38955Third Party Advisory
- http://zkteco.comNot Applicable
- https://claroty.com/team82/disclosure-dashboard/cve-2023-38955Third Party Advisory
FAQ
What is CVE-2023-38955?
CVE-2023-38955 is a vulnerability with a CVSS score of 7.5 (HIGH). ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
How severe is CVE-2023-38955?
CVE-2023-38955 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-38955?
Check the references section above for vendor advisories and patch information. Affected products include: Zkteco Bioaccess Ivs.