Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html | Third Party Advisory |
https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
21 Nov 2024, 08:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html - Third Party Advisory |
29 Aug 2023, 23:47
Type | Values Removed | Values Added |
---|---|---|
First Time |
Saho adm-100
Saho adm-100fp Firmware Saho adm-100fp Saho adm-100 Firmware Saho |
|
CPE | cpe:2.3:o:saho:adm-100_firmware:0.0.4.0:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:0.0.4.3:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:t17041702:*:*:*:*:*:*:* cpe:2.3:h:saho:adm-100:-:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100fp_firmware:t17041702:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100fp_firmware:t18051803:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:t190:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100fp_firmware:q20100602:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:0.0.4.8:*:*:*:*:*:*:* cpe:2.3:h:saho:adm-100fp:-:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100fp_firmware:t190:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:0.0.4.6:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:t18051803:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:q20100602:*:*:*:*:*:*:* |
|
References | (MISC) https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html - Third Party Advisory |
28 Aug 2023, 05:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-28 05:15
Updated : 2024-11-21 08:12
NVD link : CVE-2023-38028
Mitre link : CVE-2023-38028
CVE.ORG link : CVE-2023-38028
JSON object : View
Products Affected
saho
- adm-100fp
- adm-100_firmware
- adm-100fp_firmware
- adm-100
CWE
CWE-306
Missing Authentication for Critical Function