Vulnerability in ZKTeco FaceDepot 7B and ZKBiosecurity Server
CVE-2020-17473

5.9MEDIUM

Key Information:

Vendor

Zkteco

Vendor
CVE Published:
14 August 2020

What is CVE-2020-17473?

The ZKTeco FaceDepot 7B and ZKBiosecurity Server products are susceptible to a vulnerability due to a lack of mutual authentication. This flaw allows adversaries to impersonate the server, potentially enabling them to obtain a long-lasting security token. This vulnerability poses serious risks as it undermines the integrity of the authentication process, enabling unauthorized access and control over the features and data protected by these systems.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.