Token-Reuse Vulnerability in ZKTeco FaceDepot 7B and ZKBiosecurity Server
CVE-2020-17474

9.8CRITICAL

Key Information:

Vendor

Zkteco

Vendor
CVE Published:
14 August 2020

What is CVE-2020-17474?

A token-reuse vulnerability in ZKTeco FaceDepot 7B version 1.0.213 and ZKBiosecurity Server version 1.0.0_20190723 enables attackers to exploit insufficient token validation. This security flaw allows malicious users to create arbitrary new accounts, consolidate existing users' privileges to administrative levels, remove users from the system, and extract facial data from the database, posing a significant risk to user privacy and application integrity.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.