CVE-2023-38958: ZKTeco Bioaccess Ivs

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.

Affected products

  • ZKTeco Bioaccess Ivs: version 3.3.1 only

Published 2023-08-03. Last modified 2026-07-09.