Description
Screen SFT DAB 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP address-bound session identifiers. Attackers can exploit the vulnerable API by intercepting and reusing established sessions to remove user accounts without proper authorization.
Problem types
Product status
1.9.3
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5773.php
www.exploit-db.com/exploits/51457 (ExploitDB-51457)
www.screen.it (Product Homepage)
www.dbbroadcast.com/...cts/radio/sft-dab-series-compact-air/ (Official Product Homepage)
www.dbbroadcast.com (Vendor Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5773.php (Vendor Security Advisory for ZSL-2023-5773)
www.vulncheck.com/...cation-bypass-via-ip-session-management (VulnCheck Advisory: Screen SFT DAB 1.9.3 Authentication Bypass via IP Session Management)