CVE-2022-42953
CVSS V2 None
CVSS V3 None
Description
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
Overview
- CVE ID
- CVE-2022-42953
- Assigner
- cve@mitre.org
- Vulnerability Status
- Analyzed
- Published Version
- 2022-12-25T05:15:10
- Last Modified Date
- 2023-01-06T20:03:50
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
AND | ||||
cpe:2.3:o:zkteco:zmm200_firmware:*:*:*:*:*:*:*:* | 1 | OR | 15.00 | |
cpe:2.3:h:zkteco:zmm200:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:zkteco:zmm210_firmware:*:*:*:*:*:*:*:* | 1 | OR | 15.00 | |
cpe:2.3:h:zkteco:zmm210:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:zkteco:zmm220_firmware:*:*:*:*:*:*:*:* | 1 | OR | 15.00 | |
cpe:2.3:h:zkteco:zmm220:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:zkteco:zem720_firmware:*:*:*:*:*:*:*:* | 1 | OR | 8.88 | |
cpe:2.3:h:zkteco:zem720:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:zkteco:zem600_firmware:*:*:*:*:*:*:*:* | 1 | OR | 8.88 | |
cpe:2.3:h:zkteco:zem600:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:zkteco:zem800_firmware:*:*:*:*:*:*:*:* | 1 | OR | 8.88 | |
cpe:2.3:h:zkteco:zem800:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:zkteco:zem510_firmware:*:*:*:*:*:*:*:* | 1 | OR | 8.88 | |
cpe:2.3:h:zkteco:zem510:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:zkteco:zem560_firmware:*:*:*:*:*:*:*:* | 1 | OR | 8.88 | |
cpe:2.3:h:zkteco:zem560:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:zkteco:zem760_firmware:*:*:*:*:*:*:*:* | 1 | OR | 8.88 | |
cpe:2.3:h:zkteco:zem760:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:zkteco:zem500_firmware:*:*:*:*:*:*:*:* | 1 | OR | 8.88 | |
cpe:2.3:h:zkteco:zem500:-:*:*:*:*:*:*:* | 0 | OR |
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-42953 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42953 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-12-25 05:15:54 | Added to TrackCVE | |||
2022-12-27 14:15:38 | 2022-12-27T13:48:11 | CVE Modified Date | updated | |
2022-12-27 14:15:38 | Received | Awaiting Analysis | Vulnerability Status | updated |
2022-12-29 16:15:00 | Awaiting Analysis | Undergoing Analysis | Vulnerability Status | updated |
2023-01-06 20:18:17 | 2023-01-06T20:03:50 | CVE Modified Date | updated | |
2023-01-06 20:18:17 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2023-01-06 20:18:17 | Weakness Enumeration | new | ||
2023-01-06 20:18:18 | CPE Information | updated |