CVE-2023-38028
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: twcert@cert.org.tw (Secondary)
Description
Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.
Affected (12)
Products: Saho: Adm 100 Firmware, Adm 100fp Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 0.0.4.0 |
| Running on/with | Platform Versions |
|---|---|
Saho Adm 100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version q20100602 |
| Running on/with | Platform Versions |
|---|---|
Saho Adm 100fp | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.