NVD disclosure day

Published threat advisories for August 3, 2023

CVE advisoryCRITICAL

CVE-2023-38951

ZKTeco BioTime Arbitrary File Write and Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

ZKTeco BioTime software, used for workforce management, contains a vulnerability that allows authenticated attackers to create or overwrite arbitrary server files via crafted requests. This could lead to the execution of malicious code with system privileges. Organizations using this software should confirm its presenc

CVE advisoryKnown Exploit

CVE-2023-38950

ZKTeco BioTime Path Traversal Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in ZKTeco BioTime's iclock API allows unauthenticated attackers to read arbitrary files. This impacts organizations using the affected software by potentially exposing sensitive data. The business risk involves unauthorized access to system files.

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-38954

ZKTeco BioAccess IVS SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in ZKTeco BioAccess IVS, a system for access control and time attendance. Attackers could exploit this flaw via the network to gain unauthorized access to sensitive information or compromise the system. This could impact security operations.

CVE advisoryCRITICAL

CVE-2023-36082

GatesAir Flexiva Fax 150W Privilege Escalation via LDAP SMTP Credentials

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in GatesAir Flexiva FM transmitter equipment allows unauthenticated remote attackers to gain elevated privileges by exploiting exposed LDAP and SMTP credentials. This could impact the confidentiality, integrity, and availability of the affected system, posing a risk to broadcast infrastructure.