Vulnerability Description
Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Saho | Adm-100 Firmware | 0.0.4.0 |
| Saho | Adm-100 | - |
| Saho | Adm-100Fp Firmware | q20100602 |
| Saho | Adm-100Fp | - |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.htmlThird Party Advisory
FAQ
What is CVE-2023-38028?
CVE-2023-38028 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information ...
How severe is CVE-2023-38028?
CVE-2023-38028 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-38028?
Check the references section above for vendor advisories and patch information. Affected products include: Saho Adm-100 Firmware, Saho Adm-100, Saho Adm-100Fp Firmware, Saho Adm-100Fp.