Root Privilege Escalation Vulnerability Affects ZkTeco Devices
CVE-2023-3941
10CRITICAL
What is CVE-2023-3941?
A relative path traversal vulnerability has been identified in ZkTeco-based OEM devices. This flaw allows an attacker to exploit the system by writing files with elevated privileges. The affected devices include the ZkTeco ProFace X and various Smartec models, including ST-FR043 and ST-FR041ME, potentially exposing sensitive system areas to unauthorized modifications. Proper security measures and updates are essential to mitigate risks associated with this vulnerability.
Affected Version(s)
ZkTeco-based OEM devices with firmware ZAM170-NF-1.8.25-7354-Ver1.0.0 ZAM170-NF-1.8.25-7354-Ver1.0.0
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The vulnerability was discovered by Georgy Kiguradze from Kaspersky