Vulnerabilities > Zkteco > Bioaccess IVS

DATE CVE VULNERABILITY TITLE RISK
2023-08-03 CVE-2023-38954 SQL Injection vulnerability in Zkteco Bioaccess IVS 3.3.1
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
network
low complexity
zkteco CWE-89
critical
9.8
2023-08-03 CVE-2023-38955 Exposure of Resource to Wrong Sphere vulnerability in Zkteco Bioaccess IVS 3.3.1
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
network
low complexity
zkteco CWE-668
7.5
2023-08-03 CVE-2023-38956 Path Traversal vulnerability in Zkteco Bioaccess IVS 3.3.1
A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
network
low complexity
zkteco CWE-22
7.5
2023-08-03 CVE-2023-38958 Incorrect Authorization vulnerability in Zkteco Bioaccess IVS 3.3.1
An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.
network
low complexity
zkteco CWE-863
5.3