ZeroHour

CVE-2023-38950

KEV PoC moderate

Unauthenticated Path Traversal in ZKTeco BioTime iclock API (Arbitrary File Read)

CISA: ZKTeco BioTime Path Traversal Vulnerability

CVSS 3.1
7.5 high
EPSS
85%p100
Published
()
KEV added
AI analysis

CVE-2023-38950 is a path traversal flaw (CWE-22) in the iclock API of ZKTeco BioTime, confirmed in version 8.5.5, that lets an attacker send a crafted traversal payload to the API endpoint without any authentication. An unauthenticated remote attacker who exploits it gains the ability to read arbitrary files on the BioTime server, with high confidentiality impact but no integrity or availability impact, per the CVSS 7.5 vector. Organizations running affected BioTime deployments, particularly time-and-attendance servers reachable from the internet, are exposed. The flaw has a public proof-of-concept reference, a very high EPSS score of 84.7%, and was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-19, indicating confirmed exploitation in the wild. CISA's required action is to apply vendor mitigations (follow BOD 22-01 guidance for cloud services) or discontinue use of the product if mitigations are unavailable.

What to do: Upgrade ZKBioTime to version 9.0.120240617.19506 or later, per the vendor fix. If upgrading is not immediately possible, restrict internet exposure of the iclock API (firewall or reverse proxy) and check logs for unauthenticated requests containing traversal sequences to the endpoint; given CISA's required action for KEV entries, apply mitigations per vendor instructions or discontinue use. Since the flaw allows arbitrary file reads, review whether configuration files or credentials on the BioTime server were reachable and rotate exposed secrets as a precaution.

Affected
zkteco biotime8.5.5 confirmed affected; fixed in ZKBioTime 9.0.120240617.19506
Estimated exposure
moderateroughly thousands (1k-10k) of exposed BioTime servers; total install base unknown — ZKTeco BioTime is typically deployed as an on-premises time-and-attendance/workforce server, one per organization, so the plausible affected population is on the order of thousands of instances rather than a mass consumer base, though no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

CISA Known Exploited Vulnerability
Affected
ZKTeco BioTime
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
zkteco
Products
biotime
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news