Select your language

24 vulnerabilities found in Chinese-made biometric access system

Encuentran 24 vulnerabilidades en sistemas de acceso biométrico chinos

International. Kaspersky has identified numerous flaws in the hybrid biometric terminal produced by the international manufacturer ZKTeco. By adding random user data to the database or using a fake QR code, an actor can bypass the verification process and gain unauthorized access.

The company said attackers can also steal and exfiltrate biometric data, manipulate devices remotely, and deploy backdoors. High-security facilities around the world are at risk if they use this vulnerable device.

The flaws were discovered during an investigation by Kaspersky Security Assessment experts into the software and hardware of ZKTeco's white-label devices. All findings were proactively shared with the manufacturer prior to public disclosure.

The biometric readers in question are widely used in areas of various sectors, from nuclear or chemical plants to offices and hospitals. These devices support facial recognition and QR code authentication, in addition to the ability to store thousands of facial templates. However, the newly discovered vulnerabilities expose them to various attacks. Kaspersky grouped the flaws according to the required patches and logged them into specific CVEs (common vulnerabilities and exposures).

- Publicidad -

Physical bypass using a fake QR code
The CVE-2023-3938 vulnerability allows cybercriminals to perform a cyberattack known as SQL injection, which involves inserting malicious code into strings sent to a terminal's database. Attackers can inject specific data into the QR code used to access restricted areas. Consequently, they can gain unauthorized access to the terminal and physically access the restricted areas.

When the endpoint processes a request containing this type of malicious QR code, the database mistakenly identifies it as coming from the most recently authorized legitimate user. If the fake QR code contains an excessive amount of malicious data, instead of granting access, the device reboots.

"In addition to replacing the QR code, there is another intriguing physical attack vector. If someone with malicious intent gains access to the device's database, they can exploit other vulnerabilities to download a legitimate user's photo, print it, and use it to trick the device's camera and gain access to a secure area. This method, of course, has certain limitations. Requires a printed photograph and warmth detection must be turned off. However, it still poses a significant potential threat," says Georgy Kiguradze, Senior Application Security Specialist at Kaspersky.

Biometric data theft, backdoor implementation, and other risks
CVE-2023-3940 are flaws in a software component that allow arbitrary file reading. Exploiting these vulnerabilities grants a potential attacker access to any file on the system and allows them to extract it. This includes sensitive user biometric data and password hashes to further compromise corporate credentials. Similarly, CVE-2023-3942 provides another way to recover sensitive system and user information from biometric device databases: using SQL injection attacks.

Threat actors can not only access and steal, but also remotely alter a biometric reader's database by exploiting CVE-2023-3941. This group of vulnerabilities originates from improper verification of user input on multiple system components. Exploiting it allows attackers to upload their own data, such as photographs, thus adding unauthorized people to the database. This could allow them to stealthily get around turnstiles or gates. Another critical feature of this vulnerability allows perpetrators to replace executable files, potentially creating a backdoor.

The successful exploitation of two other groups of new flaws (CVE-2023-3939 and CVE-2023-3943) allows the execution of arbitrary commands or codes on the device, granting the attacker full control with the highest level of privileges. This allows the threat actor to manipulate the operation of the device, leveraging it to launch attacks on other nodes on the network and expand the offensive across a broader corporate infrastructure.

"The impact of the vulnerabilities discovered is alarmingly diverse. For starters, attackers can sell stolen biometric data on the dark web, subjecting affected individuals to greater risks of sophisticated attacks and social engineering. In addition, the ability to tamper with the database weaponizes the original purpose of access control devices, potentially granting access to restricted areas to nefarious actors. Finally, some vulnerabilities allow the placement of a backdoor to covertly infiltrate other enterprise networks, facilitating the development of sophisticated attacks, including cyberespionage or sabotage. All these factors underscore the urgency of fixing these vulnerabilities and thoroughly auditing the device's security settings for those who use them in corporate areas," explains Georgy Kiguradze.

- Publicidad -

At the time of publishing the information about the vulnerability, Kaspersky lacked accessible data on whether the patches have been issued. To thwart related cyberattacks, in addition to installing the patch, Kaspersky recommends following the following steps:

  • Isolate the use of the biometric reader on a separate network segment.
  • Use strong admin passwords and change the default ones.
  • Audit and strengthen device security settings, strengthening weak defaults. Consider enabling or adding temperature detection to prevent authorization using a random photo.
  • Minimize the use of QR code functionality, if possible.
  • Update the firmware periodically.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
The Challenge of Global Instability: Towards a Comprehensive Security and Defense Response

The Challenge of Global Instability: Towards a Comprehensive Security and Defense Response

The growing convergence between physical and digital threats is forcing organizations to rethink their security strategies. Faced with this scenario, there is a need for comprehensive approaches...

AI applied to medical security

AI applied to medical security

The Directorate of the Medical Emergency System (SEM), attached to the Ministry of Health of El Salvador, strengthened its technological infrastructure with the modernization of its video...

Eight Red Dot Awards Highlight Innovation in Technology Design

Eight Red Dot Awards Highlight Innovation in Technology Design

International. The technology company Ajax Systems announced that it has won eight awards in the Red Dot Design Award, one of the most prestigious global awards in the field of industrial design....

Villa María del Triunfo reinforces its security with intelligent video surveillance

Villa María del Triunfo reinforces its security with intelligent video surveillance

Peru. The district of Villa María del Triunfo has launched an intelligent video surveillance system that already shows results in terms of citizen security and that will be expanded in a second...

Milestone Systems grows 10% by 2025 and reinforces its commitment to artificial intelligence and intelligent video

Milestone Systems grows 10% by 2025 and reinforces its commitment to artificial intelligence and intelligent video

Denmark. The company reported net income of $340 million in 2025, representing a 10% growth from the previous year. The company spent about a third of this revenue on innovation, with an emphasis on...

Micro Key Solutions Reinforces Latin America Strategy with New Key Appointments

Micro Key Solutions Reinforces Latin America Strategy with New Key Appointments

United States. In response to the growth in demand for monitoring and management software solutions in the security industry, Micro Key Solutions announced the expansion of its operations in Latin...

Grupo Multisistemas strengthens its presence in Mexico with a new office in Morelia

Grupo Multisistemas strengthens its presence in Mexico with a new office in Morelia

Mexico. Grupo Multisistemas de Seguridad Industrial (GMSI) advances in its national growth strategy with the inauguration of new offices in Morelia, Michoacán, with the aim of expanding its coverage...

Case study: Security system modernization with artificial intelligence and centralized monitoring

Case study: Security system modernization with artificial intelligence and centralized monitoring

Mexico City. The Superior Audit Office of the Federation (ASF) implemented an ambitious technological renovation project in its five headquarters located in Mexico City, with the aim of...

Automated key and equipment management strengthens security in mining operations

Automated key and equipment management strengthens security in mining operations

International. Access and equipment management in the mining industry is evolving towards increasingly automated models, in response to operational complexity and occupational safety demands.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter