CVE-2023-3938

CVSS V2 None CVSS V3 None
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZkTeco-based OEM devices allows an attacker to authenticate under any user from the device database. This issue affects  ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0 and possibly others.
Overview
  • CVE ID
  • CVE-2023-3938
  • Assigner
  • Kaspersky
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-21T09:32:15.305Z
  • Last Modified Date
  • 2024-06-18T18:12:06.498Z
History
Created Old Value New Value Data Type Notes
2024-06-24 20:51:23 Added to TrackCVE