CVE-2022-42953
ZKTeco ZEM/ZMM 8.88 - Missing Authentication
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
Ciertos productos ZKTeco (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) permiten el acceso a información confidencial a través de solicitudes directas para las URL form/DataApp?style=1 y form/DataApp?style=0. Las versiones afectadas pueden ser anteriores a la 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) y 15.00 (ZMM200-220-210). Las versiones fijas son la versión de firmware 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) y la versión de firmware 15.00 (ZMM200-220-210).
ZKTeco ZEM500-510-560-760, ZEM600-800, ZEM720, and ZMM suffer from a missing authentication vulnerability. Versions below 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210) are potentially affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-15 CVE Reserved
- 2022-10-25 CVE Published
- 2023-03-28 First Exploit
- 2024-08-01 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-425: Direct Request ('Forced Browsing')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/51112 | 2023-03-28 | |
https://seclists.org/fulldisclosure/2022/Oct/23 | 2024-08-03 | |
https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyses | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zkteco Search vendor "Zkteco" | Zmm200 Firmware Search vendor "Zkteco" for product "Zmm200 Firmware" | < 15.00 Search vendor "Zkteco" for product "Zmm200 Firmware" and version " < 15.00" | - |
Affected
| in | Zkteco Search vendor "Zkteco" | Zmm200 Search vendor "Zkteco" for product "Zmm200" | - | - |
Safe
|
Zkteco Search vendor "Zkteco" | Zmm210 Firmware Search vendor "Zkteco" for product "Zmm210 Firmware" | < 15.00 Search vendor "Zkteco" for product "Zmm210 Firmware" and version " < 15.00" | - |
Affected
| in | Zkteco Search vendor "Zkteco" | Zmm210 Search vendor "Zkteco" for product "Zmm210" | - | - |
Safe
|
Zkteco Search vendor "Zkteco" | Zmm220 Firmware Search vendor "Zkteco" for product "Zmm220 Firmware" | < 15.00 Search vendor "Zkteco" for product "Zmm220 Firmware" and version " < 15.00" | - |
Affected
| in | Zkteco Search vendor "Zkteco" | Zmm220 Search vendor "Zkteco" for product "Zmm220" | - | - |
Safe
|
Zkteco Search vendor "Zkteco" | Zem720 Firmware Search vendor "Zkteco" for product "Zem720 Firmware" | < 8.88 Search vendor "Zkteco" for product "Zem720 Firmware" and version " < 8.88" | - |
Affected
| in | Zkteco Search vendor "Zkteco" | Zem720 Search vendor "Zkteco" for product "Zem720" | - | - |
Safe
|
Zkteco Search vendor "Zkteco" | Zem600 Firmware Search vendor "Zkteco" for product "Zem600 Firmware" | < 8.88 Search vendor "Zkteco" for product "Zem600 Firmware" and version " < 8.88" | - |
Affected
| in | Zkteco Search vendor "Zkteco" | Zem600 Search vendor "Zkteco" for product "Zem600" | - | - |
Safe
|
Zkteco Search vendor "Zkteco" | Zem800 Firmware Search vendor "Zkteco" for product "Zem800 Firmware" | < 8.88 Search vendor "Zkteco" for product "Zem800 Firmware" and version " < 8.88" | - |
Affected
| in | Zkteco Search vendor "Zkteco" | Zem800 Search vendor "Zkteco" for product "Zem800" | - | - |
Safe
|
Zkteco Search vendor "Zkteco" | Zem510 Firmware Search vendor "Zkteco" for product "Zem510 Firmware" | < 8.88 Search vendor "Zkteco" for product "Zem510 Firmware" and version " < 8.88" | - |
Affected
| in | Zkteco Search vendor "Zkteco" | Zem510 Search vendor "Zkteco" for product "Zem510" | - | - |
Safe
|
Zkteco Search vendor "Zkteco" | Zem560 Firmware Search vendor "Zkteco" for product "Zem560 Firmware" | < 8.88 Search vendor "Zkteco" for product "Zem560 Firmware" and version " < 8.88" | - |
Affected
| in | Zkteco Search vendor "Zkteco" | Zem560 Search vendor "Zkteco" for product "Zem560" | - | - |
Safe
|
Zkteco Search vendor "Zkteco" | Zem760 Firmware Search vendor "Zkteco" for product "Zem760 Firmware" | < 8.88 Search vendor "Zkteco" for product "Zem760 Firmware" and version " < 8.88" | - |
Affected
| in | Zkteco Search vendor "Zkteco" | Zem760 Search vendor "Zkteco" for product "Zem760" | - | - |
Safe
|
Zkteco Search vendor "Zkteco" | Zem500 Firmware Search vendor "Zkteco" for product "Zem500 Firmware" | < 8.88 Search vendor "Zkteco" for product "Zem500 Firmware" and version " < 8.88" | - |
Affected
| in | Zkteco Search vendor "Zkteco" | Zem500 Search vendor "Zkteco" for product "Zem500" | - | - |
Safe
|