CVE-2020-17474
14.08.2020, 20:15
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.Enginsight
Vendor | Product | Version |
---|---|---|
zkteco | zkbiosecurity_server | 1.0.0_20190723:_20190723 |
zkteco | facedepot_7b_firmware | 1.0.213 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References