Security Advisory

CVE-2023-38028

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-08-28 04:12:44
Last updated 2024-10-03 16:12:23
Assigner twcert
CVSS score 9.1
State PUBLISHED

Description

Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.