🔴 CVE-2023-38950

CVE-2023-38950 is a path traversal vulnerability in ZKTeco BioTime's iclock API that allows unauthenticated attackers to read arbitrary files remotely. This is actively exploited in the wild and listed in CISA's KEV catalog.

← Back to Overview
HIGH_RISK
Risk Level
7.5
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2023-08-03

Added to CISA KEV: 2025-05-19 655 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2023-38950 is a high-severity path traversal vulnerability affecting the `iclock` API in ZKTeco BioTime version 8.5.5 [1] [3].

Exploitation and Impact
  • Attack Method: The vulnerability allows an unauthenticated attacker to read arbitrary files from the server by sending a specially crafted request to the `iclock` API [1] [2].
  • Requirements: Exploitation is performed over the network and does not require user interaction or authentication [3] [2].
  • Impact: Successful exploitation provides attackers with access to sensitive information, such as configuration files or credentials, which can be used to facilitate further attacks against the affected system [2].
Active Exploitation and Threat Landscape
  • Active Exploitation: CrowdSec has been tracking this vulnerability and its exploitation since June 25, 2025 [2].
  • Usage: While the vulnerability is known to be exploited in the wild, there is no specific public documentation linking it to widespread ransomware campaigns or identifying specific threat actors using it in targeted attacks at this time.
Mitigation and Patch Status
  • Affected Version: ZKTeco BioTime v8.5.5 [1].
  • Patch Status: The vulnerability was addressed and fixed in ZKBioTime version 9.0.120240617.19506 [1] [4]. Users are advised to update to this version or later to mitigate the risk.

Sources

  1. CVE-2023-38950 Detail - NVD

    A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted ... CVE-2023-38950 Detail Description A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers…

  2. ZKBio Time - Path Traversal (CVE-2023-38950) | CrowdSec Console

    CVE-2023-38950 is a path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 which allows unauthenticated attackers to read arbitrary files on the server by sending specially crafted requests. This security flaw could be exploited to access sensitive information, configuration files,…

  3. CVE-2023-38950 | High Vulnerability in ZKTeco BioTime

    CVE-2023-38950 is a high-severity path traversal vulnerability affecting ZKTeco BioTime v8.5.5. Unauthenticated attackers can exploit this flaw ... Vulnerability Details The vulnerability detailed in CVE-2023-38950 is classified as a path traversal vulnerability affecting the iclock API of ZKTeco Bi…

  4. CVE-2023-38950 : A path traversal vulnerability in the iclock API of ...

    A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.