Screen SFT DAB 600/C <= 1.9.3 Unauthenticated Information Disclosure
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.9epss 0.3%
exploitation probability
0.3%top 72% of all CVEs
observed exploitation
nono source reports it
Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
DB Elettronica Telecomunicazioni SpA · Screen SFT DAB 600/CReferences
https://packetstormsecurity.com/files/172332/https://www.dbbroadcast.com/products/radio/sft-dab-series-compact-air/https://www.exploit-db.com/exploits/51460https://www.vulncheck.com/advisories/screen-sft-dab-600c-unauthenticated-information-disclosurehttps://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5776.php