// For flags

CVE-2022-42953

ZKTeco ZEM/ZMM 8.88 - Missing Authentication

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

Ciertos productos ZKTeco (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) permiten el acceso a información confidencial a través de solicitudes directas para las URL form/DataApp?style=1 y form/DataApp?style=0. Las versiones afectadas pueden ser anteriores a la 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) y 15.00 (ZMM200-220-210). Las versiones fijas son la versión de firmware 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) y la versión de firmware 15.00 (ZMM200-220-210).

ZKTeco ZEM500-510-560-760, ZEM600-800, ZEM720, and ZMM suffer from a missing authentication vulnerability. Versions below 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210) are potentially affected.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-10-15 CVE Reserved
  • 2022-10-25 CVE Published
  • 2023-03-28 First Exploit
  • 2024-08-01 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-425: Direct Request ('Forced Browsing')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zkteco
Search vendor "Zkteco"
Zmm200 Firmware
Search vendor "Zkteco" for product "Zmm200 Firmware"
< 15.00
Search vendor "Zkteco" for product "Zmm200 Firmware" and version " < 15.00"
-
Affected
in Zkteco
Search vendor "Zkteco"
Zmm200
Search vendor "Zkteco" for product "Zmm200"
--
Safe
Zkteco
Search vendor "Zkteco"
Zmm210 Firmware
Search vendor "Zkteco" for product "Zmm210 Firmware"
< 15.00
Search vendor "Zkteco" for product "Zmm210 Firmware" and version " < 15.00"
-
Affected
in Zkteco
Search vendor "Zkteco"
Zmm210
Search vendor "Zkteco" for product "Zmm210"
--
Safe
Zkteco
Search vendor "Zkteco"
Zmm220 Firmware
Search vendor "Zkteco" for product "Zmm220 Firmware"
< 15.00
Search vendor "Zkteco" for product "Zmm220 Firmware" and version " < 15.00"
-
Affected
in Zkteco
Search vendor "Zkteco"
Zmm220
Search vendor "Zkteco" for product "Zmm220"
--
Safe
Zkteco
Search vendor "Zkteco"
Zem720 Firmware
Search vendor "Zkteco" for product "Zem720 Firmware"
< 8.88
Search vendor "Zkteco" for product "Zem720 Firmware" and version " < 8.88"
-
Affected
in Zkteco
Search vendor "Zkteco"
Zem720
Search vendor "Zkteco" for product "Zem720"
--
Safe
Zkteco
Search vendor "Zkteco"
Zem600 Firmware
Search vendor "Zkteco" for product "Zem600 Firmware"
< 8.88
Search vendor "Zkteco" for product "Zem600 Firmware" and version " < 8.88"
-
Affected
in Zkteco
Search vendor "Zkteco"
Zem600
Search vendor "Zkteco" for product "Zem600"
--
Safe
Zkteco
Search vendor "Zkteco"
Zem800 Firmware
Search vendor "Zkteco" for product "Zem800 Firmware"
< 8.88
Search vendor "Zkteco" for product "Zem800 Firmware" and version " < 8.88"
-
Affected
in Zkteco
Search vendor "Zkteco"
Zem800
Search vendor "Zkteco" for product "Zem800"
--
Safe
Zkteco
Search vendor "Zkteco"
Zem510 Firmware
Search vendor "Zkteco" for product "Zem510 Firmware"
< 8.88
Search vendor "Zkteco" for product "Zem510 Firmware" and version " < 8.88"
-
Affected
in Zkteco
Search vendor "Zkteco"
Zem510
Search vendor "Zkteco" for product "Zem510"
--
Safe
Zkteco
Search vendor "Zkteco"
Zem560 Firmware
Search vendor "Zkteco" for product "Zem560 Firmware"
< 8.88
Search vendor "Zkteco" for product "Zem560 Firmware" and version " < 8.88"
-
Affected
in Zkteco
Search vendor "Zkteco"
Zem560
Search vendor "Zkteco" for product "Zem560"
--
Safe
Zkteco
Search vendor "Zkteco"
Zem760 Firmware
Search vendor "Zkteco" for product "Zem760 Firmware"
< 8.88
Search vendor "Zkteco" for product "Zem760 Firmware" and version " < 8.88"
-
Affected
in Zkteco
Search vendor "Zkteco"
Zem760
Search vendor "Zkteco" for product "Zem760"
--
Safe
Zkteco
Search vendor "Zkteco"
Zem500 Firmware
Search vendor "Zkteco" for product "Zem500 Firmware"
< 8.88
Search vendor "Zkteco" for product "Zem500 Firmware" and version " < 8.88"
-
Affected
in Zkteco
Search vendor "Zkteco"
Zem500
Search vendor "Zkteco" for product "Zem500"
--
Safe