Vulnerabilities (CVE)

Filtered by vendor Zkteco Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38958 1 Zkteco 1 Bioaccess Ivs 2023-08-08 N/A 5.3 MEDIUM
An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.
CVE-2020-17473 1 Zkteco 3 Facedepot 7b, Facedepot 7b Firmware, Zkbiosecurity Server 2020-08-21 4.3 MEDIUM 5.9 MEDIUM
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.
CVE-2017-17057 1 Zkteco 1 Zktime Web 2017-12-21 4.3 MEDIUM 6.1 MEDIUM
There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in the 'Range' field of the 'Department' module in a Personnel Advanced Query. A remote attacker can execute arbitrary HTML and script code in the browser in the context of the vulnerable application.