CVE-2023-53968
CRITICALScreen SFT DAB 600/C Firmware 1.9.3 - Auth Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53968. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Screen SFT DAB 600/C devices by reusing a victim's IP-bound session to delete a user account via an unauthorized API call.
Description
Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts without proper authentication.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Screen SFT DAB 600/C devices by reusing a victim's IP-bound session to delete a user account via an unauthorized API call.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H