Description

Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.

Published: 2023-08-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Contact support from Saho.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-41857 Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.
History

Thu, 03 Oct 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Saho Adm-100 Adm-100 Firmware Adm-100fp Adm-100fp Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-10-03T12:58:30.760Z

Reserved: 2023-07-12T00:37:03.717Z

Link: CVE-2023-38030

cve-icon Vulnrichment

Updated: 2024-08-02T17:30:12.343Z

cve-icon NVD

Status : Modified

Published: 2023-08-28T07:15:09.513

Modified: 2024-11-21T08:12:42.547

Link: CVE-2023-38030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses