AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-6344

LOW · CVSS 2.4 EPSS 0.38%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-06-26 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.4. It may be remotely exploitable.

CVE
CVE-2024-6344
Severity
LOW
CVSS
2.4
EPSS
0.38%

Original NVD Description

A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component. The vendor explains, that "[s]ince ZKBio CVSecurity v5000 has been withdrawn from the market, we recommend upgrading to ZKBio CVSecurity V6600 6.1.3_R or above". This vulnerability only affects products that are no longer supported by the maintainer.

Related CVEs

Other vulnerabilities affecting the same vendor(s)