An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered user backup files or device configuration files over a local network or through a VPN server.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54440 | An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered user backup files or device configuration files over a local network or through a VPN server. |
Fixes
Solution
The gama has been updated and it is recommended to upgrade to the latest version available.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-02T07:31:06.516Z
Reserved: 2023-08-29T07:42:12.425Z
Link: CVE-2023-4587
Updated: 2024-08-02T07:31:06.516Z
Status : Modified
Published: 2023-09-04T12:15:10.760
Modified: 2024-11-21T08:35:29.503
Link: CVE-2023-4587
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD