CVE-2024-35430

In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zkteco:zkbio_cvsecurity:6.1.1:*:*:*:*:*:*:*

History

09 Jul 2025, 17:15

Type Values Removed Values Added
Summary (en) In ZKTeco ZKBio CVSecurity v6.1.1 an authenticated user can bypass password checks while exporting data from the application. (en) In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the application.
References
  • () https://www.zkteco.com/en/Security_Bulletinsibs/16 -

17 Jun 2025, 19:36

Type Values Removed Values Added
First Time Zkteco zkbio Cvsecurity
Zkteco
CPE cpe:2.3:a:zkteco:zkbio_cvsecurity:6.1.1:*:*:*:*:*:*:*
References () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35430.md - () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35430.md - Exploit

21 Nov 2024, 09:20

Type Values Removed Values Added
References () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35430.md - () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35430.md -

03 Jul 2024, 02:01

Type Values Removed Values Added
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) En ZKTeco ZKBio CVSecurity v6.1.1, un usuario autenticado puede omitir las comprobaciones de contraseña mientras exporta datos desde la aplicación.

30 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-30 16:15

Updated : 2025-07-09 17:15


NVD link : CVE-2024-35430

Mitre link : CVE-2024-35430

CVE.ORG link : CVE-2024-35430


JSON object : View

Products Affected

zkteco

  • zkbio_cvsecurity
CWE
CWE-269

Improper Privilege Management