Record summary

CVE-2023-38950 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template. CISA lists CVE-2023-38950 in KEV.

Description

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · May 19, 2025 · CISA
VulnCheck KEV
Listed · May 2, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 21, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHZKTeco BioTime v8.5.5 - Path TraversalCVSS 7.5

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.

Impact

Unauthenticated attackers can read arbitrary files from the server through path traversal in the iclock API url parameter, potentially exposing employee biometric data, attendance records, and system credentials.

Remediation

Update ZKTeco BioTime to a version newer than 8.5.5 that validates file paths in the iclock API and restricts access to authorized files only.

WeaknessesCWE-22
Authorsiamnoooob, pdresearch
Template tagscvecve2023zktecobiotimelfrkevvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:zkteco:biotime:8.5.5:*:*:*:*:*:*:*
Shodan: http.title:"biotime"
FOFA: title="biotime"
Google: intitle:"biotime"

Source: ProjectDiscovery

References

6