VYPR

BioAccess IVS

by Zkteco

CVEs (4)

  • CVE-2023-38958Aug 3, 2023
    risk 0.00cvss epss 0.00

    An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.

  • CVE-2023-38956Aug 3, 2023
    risk 0.00cvss epss 0.01

    A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.

  • CVE-2023-38955Aug 3, 2023
    risk 0.00cvss epss 0.01

    ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.

  • CVE-2023-38954Aug 3, 2023
    risk 0.00cvss epss 0.01

    ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.