CVE-2023-38028

Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:saho:adm-100_firmware:0.0.4.0:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:0.0.4.3:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:0.0.4.6:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:0.0.4.8:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:q20100602:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:t190:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:t17041702:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:t18051803:*:*:*:*:*:*:*
cpe:2.3:h:saho:adm-100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:saho:adm-100fp_firmware:q20100602:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100fp_firmware:t190:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100fp_firmware:t17041702:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100fp_firmware:t18051803:*:*:*:*:*:*:*
cpe:2.3:h:saho:adm-100fp:-:*:*:*:*:*:*:*

History

29 Aug 2023, 23:47

Type Values Removed Values Added
First Time Saho
Saho adm-100 Firmware
Saho adm-100fp Firmware
Saho adm-100fp
Saho adm-100
CPE cpe:2.3:o:saho:adm-100fp_firmware:q20100602:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100fp_firmware:t18051803:*:*:*:*:*:*:*
cpe:2.3:h:saho:adm-100fp:-:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:t190:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:t17041702:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100fp_firmware:t190:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100fp_firmware:t17041702:*:*:*:*:*:*:*
cpe:2.3:h:saho:adm-100:-:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:t18051803:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:0.0.4.3:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:q20100602:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:0.0.4.6:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:0.0.4.0:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:0.0.4.8:*:*:*:*:*:*:*
References (MISC) https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html - (MISC) https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html - Third Party Advisory

28 Aug 2023, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-28 05:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-38028

Mitre link : CVE-2023-38028

CVE.ORG link : CVE-2023-38028


JSON object : View

Products Affected

saho

  • adm-100_firmware
  • adm-100fp
  • adm-100
  • adm-100fp_firmware
CWE
CWE-306

Missing Authentication for Critical Function