Attackers Can Authenticate Under Any User in ZkTeco Devices Due to SQL Injection Vulnerability
CVE-2023-3938

4.6MEDIUM

Key Information:

What is CVE-2023-3938?

A vulnerability exists in ZkTeco-based OEM devices that allows attackers to exploit improper handling of special elements in SQL commands, resulting in the potential for unauthorized access to user accounts within the device database. This flaw specifically impacts devices such as the ZkTeco ProFace X and Smartec ST-FR043, among others, particularly those operating on the ZAM170-NF-1.8.25-7354-Ver1.0.0 version and similar. Hackers can manipulate SQL queries to authenticate as any user, posing significant security risks to organizations utilizing these devices.

Affected Version(s)

ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 ZAM170-NF-1.8.25-7354-Ver1.0.0

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The vulnerability was discovered by Alexander Zaytsev from Kaspersky
.