HIGH

CVE-2022-42953

CVSS v3

7.5

HIGH

EPSS Score

15.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

Technical details

Published
12/25/2022

Frequently asked questions

What is CVE-2022-42953?

Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).

Is CVE-2022-42953 actively exploited?

Active exploitation of CVE-2022-42953 has not been confirmed. The EPSS score is 15.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-42953?

CVE-2022-42953 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2022-42953 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.