CVE-2024-35428

HIGH

Zkteco Zkbio Cvsecurity - Path Traversal

Title source: rule
STIX 2.1

Description

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS.

Scores

CVSS v3 7.1
EPSS 0.0070
EPSS Percentile 72.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
zkteco/zkbio_cvsecurity 6.1.1
Published May 30, 2024
Tracked Since Feb 18, 2026