Kaspersky finds 24 vulnerabilities in biometric access systems

Securex 2024 Information Security

Kaspersky has identified numerous flaws in the hybrid biometric terminal produced by international manufacturer ZKTeco. A nefarious actor can bypass the verification process and gain unauthorised access by adding random user data to the database or using a fake QR code. Attackers can also steal and leak biometric data, remotely manipulate devices, and deploy backdoors. High-security facilities worldwide are at risk if they use this vulnerable device.

The flaws were discovered during Kaspersky Security Assessment experts’ research into the software and hardware of ZKTeco’s white-label devices. All findings were proactively shared with the manufacturer before public disclosure.

The biometric readers in question are widely used in diverse sectors – from nuclear or chemical plants to offices and hospitals. These devices support face recognition and QR-code authentication and can store thousands of facial templates. However, the newly discovered vulnerabilities expose them to various attacks. Kaspersky grouped the flaws based on the required patches and registered them under specific CVEs (Common Vulnerabilities and Exposures).

Physical bypass via a fake QR code

The CVE-2023-3938 vulnerability allows cybercriminals to perform a cyberattack known as SQL injection, which involves inserting malicious code into strings sent to a terminal’s database. Attackers can inject specific data into the QR code used to access restricted areas. Consequently, they can gain unauthorised access to the terminal and physically access the restricted areas.

When the terminal processes a request containing this type of malicious QR code, the database mistakenly identifies it as originating from the most recently authorised legitimate user. If the fake QR code contains an excessive amount of malicious data, rather than granting access, the device restarts.

“In addition to replacing the QR code, there is another intriguing physical attack vector. If someone with malicious intent gains access to the device’s database, they can exploit other vulnerabilities to download a legitimate user’s photo, print it, and use it to deceive the device’s camera to gain access to a secured area. This method, of course, has certain limitations. It requires a printed photo, and warmth detection must be turned off. However, it still poses a significant potential threat,” says Georgy Kiguradze, Senior Application Security Specialist at Kaspersky.

Biometric data theft, backdoor deployment, and other risks

CVE-2023-3940 are flaws in a software component that permit arbitrary file reading. Exploiting these vulnerabilities grants a potential attacker access to any file on the system and enables them to extract it. This includes sensitive biometric user data and password hashes to further compromise the corporate credentials. Similarly, CVE-2023-3942 provides another way to retrieve sensitive user and system information from the biometry devices’ databases – through SQL injection attacks.

Threat actors can not only access and steal, but also remotely alter the database of a biometric reader by exploiting CVE-2023-3941. This group of vulnerabilities originates from improper verification of user input across multiple system components. Exploiting it allows attackers to upload their own data, such as photos, thereby adding unauthorised individuals to the database. This could enable them to stealthily bypass turnstiles or doors. Another critical feature of this vulnerability enables perpetrators to replace executable files, potentially creating a backdoor.

Successful exploitation of two other groups of new flaws – CVE-2023-3939 and CVE-2023-3943 – enables the execution of arbitrary commands or code on the device, granting the attacker full control with the highest level of privileges. This allows the threat actor to manipulate the device’s operation, leveraging it to launch attacks on other network nodes and expand the offence across a broader corporate infrastructure.

“The impact of the discovered vulnerabilities is alarmingly diverse. To begin with, attackers can sell stolen biometric data on the dark web, subjecting affected individuals to increased risks of deepfake and sophisticated social engineering attacks. Furthermore, the ability to alter the database weaponises the original purpose of the access control devices, potentially granting access to restricted areas for nefarious actors. Lastly, some vulnerabilities enable the placement of a backdoor to covertly infiltrate other enterprise networks, facilitating the development of sophisticated attacks, including cyberespionage or sabotage. All these factors underscore the urgency of patching these vulnerabilities and thoroughly auditing the device's security settings for those using the devices in corporate areas,” elaborates Kiguradze.

To thwart related cyberattacks, besides installing the patch, Kaspersky advises taking the following steps:

• Isolate biometric reader usage into a separate network segment.

• Employ robust administrator passwords, changing default ones.

• Audit and bolster devices' security settings, fortifying weak defaults. Consider enabling or adding temperature detection to avoid authorisation using a random photo.

• Minimise the use of QR-code functionality, if feasible.

• Update firmware regularly.

Learn more on Securelist.com.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

SanDisk MAX ENDURANCE microSD card
Technews Publishing SMART Security Solutions Smart Home Automation Products & Solutions
SMART Security Solutions received a 128 GB SanDisk microSD card for the video surveillance market to put to the test. The storage card is designed for edge-recording cameras, dashcams, and more.

Read more...
The dangers of parked domains
Information Security
Kaspersky warns that fraudsters are exploiting so-called ‘parked domains’ to harvest sensitive personal data from unsuspecting users. These deceptive sites often masquerade as error pages or ad-filled placeholders, exposing users to privacy breaches and potential identity theft.

Read more...
Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Buying more security tools is not building a defence
Information Security
Sophisticated attacks are specifically engineered to bypass individual security tools, and companies absorbing the damage are those who have confused procurement with protection, says Richard Frost from Armata Cyber Security.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Hold the line
BlueVision Information Security Editor's Choice
While most businesses are still focused on guarding the wall, the perimeter today has moved to the login screen, according to Christo Coetzer, founder and managing director of BlueVision Technologies.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...
BlueVision launches Fusion Cloud
BlueVision Information Security Products & Solutions
Most businesses have moved to the cloud, including Microsoft 365, Azure, AWS and more, and in doing so assume they're protected because they're using a reputable platform; however, the reality is somewhat different.

Read more...
Tools detect threats: Cyber resilience protects businesses
Information Security
If your cybersecurity strategy is built around buying Managed Detection and Response (MDR), deploying an Endpoint Detection and Response (EDR) agent, and calling it ‘done’, then someone has sold you a story, not a strategy.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.