High severity7.5CISA KEVNVD Advisory· Published Aug 3, 2023· Updated Jul 9, 2026
CVE-2023-38950
CVE-2023-38950
Description
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <9.0.120240617.19506
Patches
Vulnerability mechanics
References
4- sploitus.com/exploitnvdExploit
- claroty.com/team82/disclosure-dashboard/cve-2023-38950nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.fortinet.com/content/dam/fortinet/assets/reports/report-incident-response-middle-east.pdfnvdBroken LinkTechnical Description
News mentions
0No linked articles in our index yet.