Root Privilege Escalation Vulnerability Affects ZkTeco Devices
CVE-2023-3941

10CRITICAL

Key Information:

What is CVE-2023-3941?

A relative path traversal vulnerability has been identified in ZkTeco-based OEM devices. This flaw allows an attacker to exploit the system by writing files with elevated privileges. The affected devices include the ZkTeco ProFace X and various Smartec models, including ST-FR043 and ST-FR041ME, potentially exposing sensitive system areas to unauthorized modifications. Proper security measures and updates are essential to mitigate risks associated with this vulnerability.

Affected Version(s)

ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 ZAM170-NF-1.8.25-7354-Ver1.0.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The vulnerability was discovered by Georgy Kiguradze from Kaspersky
.