CVE-2023-38955

HIGH

ZKTeco BioAccess IVS <3.3.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.

Scores

CVSS v3 7.5
EPSS 0.0015
EPSS Percentile 35.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-668
Status published
Products (1)
zkteco/bioaccess_ivs 3.3.1
Published Aug 03, 2023
Tracked Since Feb 18, 2026