ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerate valid user accounts based on application responses.
An attacker sends HTTP requests to the authLoginAction!login.do script, providing various partial character strings in the username parameter. The application returns different responses depending on whether the provided fragment corresponds to an existing user account. Based on analysis of these response differences, it is possible to systematically discover and confirm valid account names without requiring any authentication.
An attacker is able to identify a list of valid usernames in the ZKBioSecurity system, which can be leveraged as a starting point for further attacks, such as dictionary attacks or brute-force password attacks on these accounts.
Patches available from the manufacturer should be applied according to references. Additionally, it is recommended to restrict access to the application's web interface only to trusted networks and implement monitoring and blocking mechanisms for suspicious numbers of requests to the authLoginAction!login.do endpoint.
ZKTeco ZKBioSecurity version 3.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X