Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41857 | Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions. |
Fixes
Solution
Contact support from Saho.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7337-501df-1.html |
|
History
Thu, 03 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-10-03T12:58:30.760Z
Reserved: 2023-07-12T00:37:03.717Z
Link: CVE-2023-38030
Updated: 2024-08-02T17:30:12.343Z
Status : Modified
Published: 2023-08-28T07:15:09.513
Modified: 2024-11-21T08:12:42.547
Link: CVE-2023-38030
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD