LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2016-20031

Published
CVSS5.5
Severitymedium
WeaknessCWE-798
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers can exploit the EnvironmentUtil.getClientIp() method which treats IPv6 loopback address 0:0:0:0:0:0:0:1 as 127.0.0.1 and authenticates using the IP as username with hardcoded password 123456 to access sensitive information and perform unauthorized actions.

References

← Back to the CVE Tracker

Our coverage of CVE-2016-20031

No stories yet. This page updates automatically when we publish reporting that references CVE-2016-20031.