Biotime
Vendor:
First CVE: Nov 8, 2022 · Active for 3 years
12
Total CVEs
More Total CVEs than 91% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
8.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Biotime over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2022
3 years ago
Most Recent CVE
May 27, 2025
427 days ago
CVE Severity & Scoring
Biotime12 CVEs
50%
42%
8%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (66.7%)
Unknown0 (0.0%)
Required4 (33.3%)
Privileges Required
Low4 (33.3%)
High1 (8.3%)
None7 (58.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38950HIGH A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerabili | Aug 3, 2023 | 7.5 | 96 | YES | YES |
CVE-2023-38952HIGH Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type | Aug 3, 2023 | 7.5 | 34 | NO | YES |
CVE-2023-38951CRITICAL ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sft | Aug 3, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-38803MEDIUM Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can read local files by exploiting XS | Nov 30, 2022 | 6.8 | 23 | NO | NO |
CVE-2023-51142HIGH An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information. | Apr 11, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-38949HIGH An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request. | Aug 3, 2023 | 7.5 | 22 | NO | NO |
CVE-2022-38802MEDIUM Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, time interval, attshift, and holiday. An authenticated | Nov 30, 2022 | 6.2 | 22 | NO | NO |
CVE-2024-13966HIGH ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their p | May 27, 2025 | 7.3 | 21 | NO | NO |
CVE-2023-51141MEDIUM An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization component | Apr 11, 2024 | 6.5 | 21 | NO | NO |
CVE-2022-38801MEDIUM In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-site scripting. | Nov 30, 2022 | 5.4 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
1 CVE
8.3% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
16.7% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Biotime
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.5.5 | 4 | 7.5 | 1.7% | 0 | 1 |
| 8.5.4 | 3 | 6.4 | 0.7% | 0 | 0 |