CVE-2023-38950
KEV High · CVSS 7.5ZKTeco BioTime — Path Traversal (Unauthenticated Arbitrary File Read)
- CVSS
- 7.5
- nvd
- EPSS
- 84.9%
- 100th pct
- KEV
- Listed
- 2025-05-19
- Class
- other
- CWE-22, CWE-22
Description
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
Search profile — drives PoC discovery
Symbols iclockiclock APIBioTimeZKBioTime/iclock/path traversal payload
Keywords CVE-2023-38950ZKTeco BioTime path traversalBioTime iclock API exploitZKBioTime arbitrary file readBioTime unauthenticated file read PoCZKTeco iclock directory traversal
Versions: ≤ 8.5.5 (fixed in ZKBioTime 9.0.120240617.19506)
Ranked PoCs (2) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0packetinside/CISA_BOT needs reviewtrickest
- ★ 0ums91/CISA_BOT needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://claroty.com/team82/disclosure-dashboard/cve-2023-38950
- https://claroty.com/team82/disclosure-dashboard/cve-2023-38950
- https://sploitus.com/exploit?id=PACKETSTORM:177859
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38950
- https://www.fortinet.com/content/dam/fortinet/assets/reports/report-incident-response-middle-east.pdf
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z