Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html | Third Party Advisory |
https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
21 Nov 2024, 08:12
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-28 05:15
Updated : 2024-11-21 08:12
NVD link : CVE-2023-38028
Mitre link : CVE-2023-38028
CVE.ORG link : CVE-2023-38028
JSON object : View
Products Affected
saho
- adm-100
- adm-100_firmware
- adm-100fp_firmware
- adm-100fp
CWE
CWE-306
Missing Authentication for Critical Function