CVE-2023-53969
7.5DB Elettronica Telecomunicazioni SpA · Screen SFT DAB 600/C
The Screen SFT DAB 600/C transmitter contains a session management vulnerability allowing unauthenticated attackers to bypass authentication and modify user passwords via the userManager API.
Executive summary
A critical session management flaw in the Screen SFT DAB 600/C transmitter allows unauthenticated attackers to hijack sessions and reset administrative passwords.
Vulnerability
The device suffers from improper session binding where the application relies solely on the source IP address for session tracking. An unauthenticated attacker can observe an active session and perform unauthorized requests to the /system/api/userManager.cgx endpoint to manipulate administrative credentials.
Business impact
Successful exploitation of this vulnerability grants an attacker full control over the DAB transmitter. Given the device's role in broadcasting infrastructure, compromise could lead to unauthorized service disruption, signal manipulation, or permanent loss of administrative access. The CVSS score of 7.5 reflects the high impact on confidentiality, integrity, and availability, necessitating urgent remediation for critical infrastructure components.
Remediation
Immediate Action: Contact the vendor, DB Elettronica Telecomunicazioni SpA, to obtain and apply the latest firmware security update that addresses the session management flaw.
Proactive Monitoring: Monitor network traffic for unauthorized access attempts directed at the /system/api/userManager.cgx endpoint and review system access logs for anomalous password change events.
Compensating Controls: Restrict access to the management interface of the SFT DAB 600/C to trusted management networks only and utilize a firewall to block public internet access to the device's administrative web API.
Exploitation status
Public Exploit Available: Yes, a functional exploit script is available via Exploit-DB (EDB-ID: 51456).
Analyst recommendation
This vulnerability presents a significant risk to the integrity of broadcast operations. Administrators must prioritize updating the firmware on all affected SFT DAB 600/C units to the version recommended by the vendor. In environments where immediate patching is not feasible, ensure that the device management interface is completely isolated from public-facing networks to prevent remote exploitation.
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- ExploitDB-51456 Exploit / PoC
- DB Elettronica Telecomunicazioni Official Website
- SFT DAB Series Product Page
- Zero Science Lab Disclosure (ZSL-2022-5772) Third-party advisory
- VulnCheck Advisory: Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Password Change Third-party advisory