PT-2023-4125 · Zkteco · Zkteco Bioaccess Ivs

CVE-2023-38954

·

Publicado

2023-07-25

·

Atualizado

2023-08-07

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ZKTeco BioAccess IVS version 3.3.1
Description The issue is related to a lack of protection for the SQL query structure, which can be exploited to execute arbitrary SQL code. This can be done remotely.
Recommendations For ZKTeco BioAccess IVS version 3.3.1, consider restricting access to the SQL database to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using user-input data in SQL queries to prevent injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04434
CVE-2023-38954

Produtos afetados

Zkteco Bioaccess Ivs