Vulnerability Description
Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Saho | Adm-100 Firmware | 0.0.4.0 |
| Saho | Adm-100 | - |
| Saho | Adm-100Fp Firmware | q20100602 |
| Saho | Adm-100Fp | - |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-7337-501df-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-7337-501df-1.htmlThird Party Advisory
FAQ
What is CVE-2023-38030?
CVE-2023-38030 is a vulnerability with a CVSS score of 7.5 (HIGH). Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website...
How severe is CVE-2023-38030?
CVE-2023-38030 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-38030?
Check the references section above for vendor advisories and patch information. Affected products include: Saho Adm-100 Firmware, Saho Adm-100, Saho Adm-100Fp Firmware, Saho Adm-100Fp.