CVE-2023-38028

Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:saho:adm-100_firmware:0.0.4.0:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:0.0.4.3:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:0.0.4.6:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:0.0.4.8:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:q20100602:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:t190:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:t17041702:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100_firmware:t18051803:*:*:*:*:*:*:*
cpe:2.3:h:saho:adm-100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:saho:adm-100fp_firmware:q20100602:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100fp_firmware:t190:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100fp_firmware:t17041702:*:*:*:*:*:*:*
cpe:2.3:o:saho:adm-100fp_firmware:t18051803:*:*:*:*:*:*:*
cpe:2.3:h:saho:adm-100fp:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:12

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-28 05:15

Updated : 2024-11-21 08:12


NVD link : CVE-2023-38028

Mitre link : CVE-2023-38028

CVE.ORG link : CVE-2023-38028


JSON object : View

Products Affected

saho

  • adm-100
  • adm-100_firmware
  • adm-100fp_firmware
  • adm-100fp
CWE
CWE-306

Missing Authentication for Critical Function