Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.
History

Thu, 11 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast
Dbbroadcast sft Dab Series
Vendors & Products Dbbroadcast
Dbbroadcast sft Dab Series

Wed, 10 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
Description Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.
Title Screen SFT DAB 1.9.3 Authentication Bypass via Session Management Weakness
Weaknesses CWE-384
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-10T21:08:11.707Z

Updated: 2025-12-11T18:52:11.478Z

Reserved: 2025-12-08T23:43:00.992Z

Link: CVE-2023-53775

cve-icon Vulnrichment

Updated: 2025-12-11T15:51:43.708Z

cve-icon NVD

Status : Received

Published: 2025-12-10T22:16:18.363

Modified: 2025-12-11T19:15:51.917

Link: CVE-2023-53775

cve-icon Redhat

No data.