Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-53970. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit bypasses authentication by reusing a victim's IP-bound session to send unauthorized API requests, specifically triggering a device reset on the Screen SFT DAB 600/C transmitter.
Description
Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations by sending crafted POST requests with manipulated session parameters.
Exploits (1)
This exploit bypasses authentication by reusing a victim's IP-bound session to send unauthorized API requests, specifically triggering a device reset on the Screen SFT DAB 600/C transmitter.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N