Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-53969. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Screen SFT DAB 600/C devices by reusing a victim's IP-bound session to change user credentials via an unauthorized API call. It leverages weak session management to manipulate the transmitter's user settings.
Description
Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords without proper authentication.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Screen SFT DAB 600/C devices by reusing a victim's IP-bound session to change user credentials via an unauthorized API call. It leverages weak session management to manipulate the transmitter's user settings.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N