Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.
History

Thu, 03 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2023-08-28T04:12:44.854Z

Updated: 2024-10-03T16:12:23.404Z

Reserved: 2023-07-12T00:37:03.717Z

Link: CVE-2023-38028

cve-icon Vulnrichment

Updated: 2024-08-02T17:23:28.093Z

cve-icon NVD

Status : Modified

Published: 2023-08-28T05:15:07.667

Modified: 2024-11-21T08:12:42.270

Link: CVE-2023-38028

cve-icon Redhat

No data.