CVE-2023-53968
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts without proper authentication.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| DB Elettronica Telecomunicazioni SpA | Screen SFT DAB 600/C | — | - |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-306 | cna | Missing Authentication for Critical Function |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 9.3 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
References (5)
- ExploitDB-51457 https://www.exploit-db.com/exploits/51457
- DB Elettronica Telecomunicazioni Official Website https://www.dbbroadcast.com
- SFT DAB Series Product Page https://www.dbbroadcast.com/products/radio/sft-dab-series-compact-air/
- Zero Science Lab Disclosure (ZSL-2022-5773) https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5773.php
- VulnCheck Advisory: Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Erase Account https://www.vulncheck.com/advisories/screen-sft-dab-c-firmware-authentication-bypass-erase-account