{ "schema_version": "1.4.0", "id": "GHSA-54r9-6x6g-2vfv", "modified": "2023-01-06T21:30:41Z", "published": "2022-12-25T06:30:21Z", "aliases": [ "CVE-2022-42953" ], "details": "Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42953" }, { "type": "WEB", "url": "https://seclists.org/fulldisclosure/2022/Oct/23" }, { "type": "WEB", "url": "https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyses" } ], "database_specific": { "cwe_ids": [ "CWE-425", "CWE-668" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2022-12-25T05:15:00Z" } }