CVE-2023-38951

ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zkteco:biotime:8.5.5:*:*:*:*:*:*:*

History

24 May 2025, 14:15

Type Values Removed Values Added
References
  • () https://www.zkteco.com/en/ZKBio_Time/ZKBioTime#Download -
  • () https://www.zkteco.com/en/announcement -
Summary (en) ZKTeco BioTime version 8.5.5 through 9.0.1 allows authenticated attackers to create or overwrite arbitrary files on the server by making specially crafted requests to '/base/sftpsetting/' endpoints that abuse a path traversal issue in the 'Username' field and a lack of input sanitization on the 'SSH Key' field. Overwriting specific files may lead to arbitrary code execution as the 'NT AUTHORITY\SYSTEM' user. (en) ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.

19 May 2025, 22:15

Type Values Removed Values Added
Summary (en) A path traversal vulnerability in ZKTeco BioTime v8.5.5 allows attackers to write arbitrary files via using a malicious SFTP configuration. (en) ZKTeco BioTime version 8.5.5 through 9.0.1 allows authenticated attackers to create or overwrite arbitrary files on the server by making specially crafted requests to '/base/sftpsetting/' endpoints that abuse a path traversal issue in the 'Username' field and a lack of input sanitization on the 'SSH Key' field. Overwriting specific files may lead to arbitrary code execution as the 'NT AUTHORITY\SYSTEM' user.
References
  • () https://github.com/omair2084/biotime-rce-8.5.5/blob/main/biotime_enum.py -
  • () https://krashconsulting.com/fury-of-fingers-biotime-rce/ -

05 May 2025, 15:15

Type Values Removed Values Added
References
  • () https://sploitus.com/exploit?id=PACKETSTORM:177859 -

21 Nov 2024, 08:14

Type Values Removed Values Added
References () http://zkteco.com - Product () http://zkteco.com - Product
References () https://claroty.com/team82/disclosure-dashboard/cve-2023-38951 - Third Party Advisory () https://claroty.com/team82/disclosure-dashboard/cve-2023-38951 - Third Party Advisory

08 Aug 2023, 19:02

Type Values Removed Values Added
CPE cpe:2.3:a:zkteco:biotime:8.5.5:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) http://zkteco.com - (MISC) http://zkteco.com - Product
References (MISC) https://claroty.com/team82/disclosure-dashboard/cve-2023-38951 - (MISC) https://claroty.com/team82/disclosure-dashboard/cve-2023-38951 - Third Party Advisory
CWE CWE-22

03 Aug 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-03 23:15

Updated : 2025-05-27 20:15


NVD link : CVE-2023-38951

Mitre link : CVE-2023-38951

CVE.ORG link : CVE-2023-38951


JSON object : View

Products Affected

zkteco

  • biotime
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')