A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 08 Nov 2025 04:15:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:zkteco:biotime:8.5.5:*:*:*:*:*:*:* cpe:2.3:a:zkteco:biotime:*:*:*:*:*:*:*:*

Wed, 05 Nov 2025 02:15:00 +0900

Type Values Removed Values Added
Description A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

Wed, 22 Oct 2025 08:30:00 +0900


Wed, 22 Oct 2025 05:30:00 +0900


Wed, 22 Oct 2025 04:30:00 +0900


Sun, 13 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.84784}

epss

{'score': 0.82484}


Tue, 20 May 2025 08:15:00 +0900

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-05-19'}


Tue, 20 May 2025 04:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 May 2025 03:30:00 +0900


Tue, 06 May 2025 00:15:00 +0900

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Oct 2024 01:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-04T16:56:10.466Z

Reserved: 2023-07-25T00:00:00.000Z

Link: CVE-2023-38950

cve-icon Vulnrichment

Updated: 2024-08-02T17:54:39.722Z

cve-icon NVD

Status : Analyzed

Published: 2023-08-03T23:15:11.117

Modified: 2025-11-07T19:02:59.793

Link: CVE-2023-38950

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses