Vulnerability Description
A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zkteco | Bioaccess Ivs | 3.3.1 |
Related Weaknesses (CWE)
References
- http://zkteco.comNot Applicable
- https://claroty.com/team82/disclosure-dashboard/cve-2023-38956Third Party Advisory
- http://zkteco.comNot Applicable
- https://claroty.com/team82/disclosure-dashboard/cve-2023-38956Third Party Advisory
FAQ
What is CVE-2023-38956?
CVE-2023-38956 is a vulnerability with a CVSS score of 7.5 (HIGH). A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
How severe is CVE-2023-38956?
CVE-2023-38956 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-38956?
Check the references section above for vendor advisories and patch information. Affected products include: Zkteco Bioaccess Ivs.