Bioaccess Ivs
by Zkteco
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38954 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2023 | ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2023-38956 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2023 | A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. | ||
| CVE-2023-38955 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2023 | ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names. | ||
| CVE-2023-38958 | Med | 0.34 | 5.3 | 0.00 | Aug 3, 2023 | An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request. |
- risk 0.64cvss 9.8epss 0.01
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
- risk 0.49cvss 7.5epss 0.01
A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.
- risk 0.49cvss 7.5epss 0.01
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
- risk 0.34cvss 5.3epss 0.00
An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.