Token-Reuse Vulnerability in ZKTeco FaceDepot 7B and ZKBiosecurity Server
CVE-2020-17474
9.8CRITICAL
What is CVE-2020-17474?
A token-reuse vulnerability in ZKTeco FaceDepot 7B version 1.0.213 and ZKBiosecurity Server version 1.0.0_20190723 enables attackers to exploit insufficient token validation. This security flaw allows malicious users to create arbitrary new accounts, consolidate existing users' privileges to administrative levels, remove users from the system, and extract facial data from the database, posing a significant risk to user privacy and application integrity.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved