CVE-2020-17474

CRITICAL

ZKTeco FaceDepot <7B-1.0.213 & ZKBiosecurity - Privilege Escalation

Title source: llm
STIX 2.1

Description

A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.

Scores

CVSS v3 9.8
EPSS 0.0118
EPSS Percentile 63.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-613
Status published
Products (2)
zkteco/facedepot_7b_firmware 1.0.213
zkteco/zkbiosecurity_server 1.0.0_20190723
Published Aug 14, 2020
Tracked Since Feb 18, 2026