Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.
History

Thu, 03 Oct 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2023-08-28T06:44:16.870Z

Updated: 2024-10-03T12:58:30.760Z

Reserved: 2023-07-12T00:37:03.717Z

Link: CVE-2023-38030

cve-icon Vulnrichment

Updated: 2024-08-02T17:30:12.343Z

cve-icon NVD

Status : Modified

Published: 2023-08-28T07:15:09.513

Modified: 2024-11-21T08:12:42.547

Link: CVE-2023-38030

cve-icon Redhat

No data.