CVE-2023-38950
KEV PoC moderateUnauthenticated Path Traversal in ZKTeco BioTime iclock API (Arbitrary File Read)
CISA: ZKTeco BioTime Path Traversal Vulnerability
CVE-2023-38950 is a path traversal flaw (CWE-22) in the iclock API of ZKTeco BioTime, confirmed in version 8.5.5, that lets an attacker send a crafted traversal payload to the API endpoint without any authentication. An unauthenticated remote attacker who exploits it gains the ability to read arbitrary files on the BioTime server, with high confidentiality impact but no integrity or availability impact, per the CVSS 7.5 vector. Organizations running affected BioTime deployments, particularly time-and-attendance servers reachable from the internet, are exposed. The flaw has a public proof-of-concept reference, a very high EPSS score of 84.7%, and was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-19, indicating confirmed exploitation in the wild. CISA's required action is to apply vendor mitigations (follow BOD 22-01 guidance for cloud services) or discontinue use of the product if mitigations are unavailable.
What to do: Upgrade ZKBioTime to version 9.0.120240617.19506 or later, per the vendor fix. If upgrading is not immediately possible, restrict internet exposure of the iclock API (firewall or reverse proxy) and check logs for unauthenticated requests containing traversal sequences to the endpoint; given CISA's required action for KEV entries, apply mitigations per vendor instructions or discontinue use. Since the flaw allows arbitrary file reads, review whether configuration files or credentials on the BioTime server were reachable and rotate exposed secrets as a precaution.
| zkteco biotime | 8.5.5 confirmed affected; fixed in ZKBioTime 9.0.120240617.19506 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
- Affected
- ZKTeco BioTime
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- zkteco
- Products
- biotime
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N