CVE-2023-3941
EUVD-2023-4456721.05.2024, 11:15
Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system with root privileges. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0 and possibly others.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| zkteco | smartec_st_fr041me | 𝑥 ≤ ZAM170-NF-1.8.25-7354-Ver1.0.0 | ADP |
| zkteco | facedepot_7b | 𝑥 ≤ ZAM170-NF-1.8.25-7354-Ver1.0.0 | ADP |
| zkteco | smartec_st_fr043 | 𝑥 ≤ ZAM170-NF-1.8.25-7354-Ver1.0.0 | ADP |