vendor:
by:
FB1H2S
N/A
CVSS
N/A
Improper Authentication
Unknown
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2010
ZKSoftware Biometric Attendence managnmnet Hardware[MIPS] Improper Authentication
ZKSoftware is a biometric attendance management system that allows remote IP based management of the hardware via UDP protocol without proper authentication. This vulnerability allows an attacker to send custom commands and download information from the system. The Etimetrack software used to manage the hardware has a hard-coded encryption key, making it susceptible to exploitation.
Mitigation:
Unknown