Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41855 | Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service. |
Fixes
Solution
Contact support from Saho.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7335-d300a-1.html |
|
History
Thu, 03 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-10-03T16:12:23.404Z
Reserved: 2023-07-12T00:37:03.717Z
Link: CVE-2023-38028
Updated: 2024-08-02T17:23:28.093Z
Status : Modified
Published: 2023-08-28T05:15:07.667
Modified: 2024-11-21T08:12:42.270
Link: CVE-2023-38028
No data.
OpenCVE Enrichment
No data.
EUVD