CVE-2023-38950
CISA 기관 조치 기한: 2025-06-09
ZKTeco BioTime
Qualys 위협 인텔 · 심각도 4/5 · QID 732606 · CGI
공개 익스플로잇
쉬운 악용
대량 데이터 유출
CISA KEV
ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.
KEV 필수 조치: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.