CVE-2023-53969
critical · 9.3Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords without proper authentication.
9.3
CVSS
0.5%
EPSS (exploit prob.)
43rd
EPSS percentile
2025-12-22
Published
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-306
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| dbbroadcast | sft_dab_600/c_firmware | 1.9.3 |
| dbbroadcast | sft_dab_600/c | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://www.dbbroadcast.com
- https://www.dbbroadcast.com/products/radio/sft-dab-series-compact-air/
- https://www.exploit-db.com/exploits/51456
- https://www.vulncheck.com/advisories/screen-sft-dab-c-firmware-authentication-bypass-password-change
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5772.php
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5772.php
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-53969