CVE-2023-53776
HIGHScreen SFT DAB 1.9.3 - Authentication Bypass via Session Fixation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53776. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit bypasses authentication by reusing a victim's IP-bound session to send unauthorized API requests, specifically triggering a device reset on the Screen SFT DAB 600/C transmitter.
Description
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to exploit weak session management by reusing IP-bound session identifiers. Attackers can issue unauthorized requests to the device management API by leveraging the session binding mechanism to perform critical operations on the transmitter.
Exploits (1)
This exploit bypasses authentication by reusing a victim's IP-bound session to send unauthorized API requests, specifically triggering a device reset on the Screen SFT DAB 600/C transmitter.
References (6)
Scores
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H