← Back

CVE-2023-38028

nvd nist
Published: Aug 28, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: twcert@cert.org.tw (Secondary)

Description

Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.

Affected (12)

2 products
Adm 100 Firmware
Adm 100fp Firmware
Configuration A
8 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Saho
Version 0.0.4.0
Version 0.0.4.3
Version 0.0.4.6
Version 0.0.4.8
Version q20100602
Version t17041702
Version t18051803
Version t190
Running on/withPlatform Versions
Saho
Adm 100
All versions
Configuration B
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Saho
Version q20100602
Version t17041702
Version t18051803
Version t190
Running on/withPlatform Versions
Saho
Adm 100fp
All versions

References (2)

Source: twcert@cert.org.tw
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.