CVE-2023-53970

7.5

DB Elettronica Telecomunicazioni SpA · Screen SFT DAB 600/C

The Screen SFT DAB 600/C device contains a weak session management vulnerability that allows attackers to perform unauthorized configuration resets via the deviceManagement API.

Executive summary

A critical authentication bypass vulnerability in the Screen SFT DAB 600/C firmware allows unauthenticated remote attackers to reset device configurations, posing a significant risk to operational integrity.

Vulnerability

The device suffers from weak session management where session identifiers are bound solely to the IP address. An unauthenticated attacker on the same network can hijack a valid session by spoofing the victim's IP address and sending crafted POST requests to the deviceManagement API endpoint.

Business impact

Successful exploitation of this vulnerability allows an attacker to reset the configuration of the affected transmitter, which can lead to extended service outages and loss of control over critical broadcasting infrastructure. Given the CVSS score of 7.5, this high severity flaw represents a significant risk to operational availability and management control, as the attacker can perform administrative actions without prior authentication.

Remediation

Immediate Action: Contact the vendor, DB Elettronica Telecomunicazioni SpA, to obtain the latest firmware updates. If a specific patch is not yet available, restrict network access to the transmitter management interface to trusted administrative subnets only.

Proactive Monitoring: Review system logs for unauthorized access attempts or unexpected configuration reset commands originating from unknown or suspicious IP addresses.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall or an access control list to block unauthorized requests to the /system/api/deviceManagement.cgx endpoint.

Exploitation status

Public Exploit Available: Yes, a proof of concept exploit script is available on ExploitDB (EDB-ID: 51459).

Analyst recommendation

Due to the availability of public exploit code and the critical nature of the device configuration, administrators must treat this vulnerability with high urgency. Immediately isolate the management interface of the affected SFT DAB 600/C units from public or untrusted networks and apply vendor-supplied firmware updates as soon as they become available.

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.