Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
29 Aug 2023, 23:47
Type | Values Removed | Values Added |
---|---|---|
First Time |
Saho
Saho adm-100 Firmware Saho adm-100fp Firmware Saho adm-100fp Saho adm-100 |
|
CPE | cpe:2.3:o:saho:adm-100fp_firmware:q20100602:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100fp_firmware:t18051803:*:*:*:*:*:*:* cpe:2.3:h:saho:adm-100fp:-:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:t190:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:t17041702:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100fp_firmware:t190:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100fp_firmware:t17041702:*:*:*:*:*:*:* cpe:2.3:h:saho:adm-100:-:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:t18051803:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:0.0.4.3:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:q20100602:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:0.0.4.6:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:0.0.4.0:*:*:*:*:*:*:* cpe:2.3:o:saho:adm-100_firmware:0.0.4.8:*:*:*:*:*:*:* |
|
References | (MISC) https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html - Third Party Advisory |
28 Aug 2023, 05:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-28 05:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-38028
Mitre link : CVE-2023-38028
CVE.ORG link : CVE-2023-38028
JSON object : View
Products Affected
saho
- adm-100_firmware
- adm-100fp
- adm-100
- adm-100fp_firmware
CWE
CWE-306
Missing Authentication for Critical Function