Loading
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
Use CWE-22, Zkteco vendor hub and Biotime product page to widen CVE-2023-38950 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-38951, CVE-2023-51142 and CVE-2023-38952 for nearby disclosures in the same product family.