CVE-2023-4587 is an Insecure Direct Object Reference (IDOR) vulnerability affecting ZKTeco ZEM800 products, specifically version 6.60. This flaw allows a local attacker to access sensitive data such as user backup files or device configuration files over a local network or VPN. The vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and requiring local access, but with a high impact on confidentiality. It does not affect integrity or availability. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.60CPE matchmatch criteria | cpe:2.3:o:zkteco:zem800_firmware:6.60:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.