HIGH · 7.5

CVE-2023-38030

Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website...

Vulnerability Description

Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SahoAdm-100 Firmware0.0.4.0
SahoAdm-100-
SahoAdm-100Fp Firmwareq20100602
SahoAdm-100Fp-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-38030?

CVE-2023-38030 is a vulnerability with a CVSS score of 7.5 (HIGH). Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website...

How severe is CVE-2023-38030?

CVE-2023-38030 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-38030?

Check the references section above for vendor advisories and patch information. Affected products include: Saho Adm-100 Firmware, Saho Adm-100, Saho Adm-100Fp Firmware, Saho Adm-100Fp.