CVE-2023-53970
7.5DB Elettronica Telecomunicazioni SpA · Screen SFT DAB 600/C
The Screen SFT DAB 600/C device contains a weak session management vulnerability that allows attackers to perform unauthorized configuration resets via the deviceManagement API.
Executive summary
A critical authentication bypass vulnerability in the Screen SFT DAB 600/C firmware allows unauthenticated remote attackers to reset device configurations, posing a significant risk to operational integrity.
Vulnerability
The device suffers from weak session management where session identifiers are bound solely to the IP address. An unauthenticated attacker on the same network can hijack a valid session by spoofing the victim's IP address and sending crafted POST requests to the deviceManagement API endpoint.
Business impact
Successful exploitation of this vulnerability allows an attacker to reset the configuration of the affected transmitter, which can lead to extended service outages and loss of control over critical broadcasting infrastructure. Given the CVSS score of 7.5, this high severity flaw represents a significant risk to operational availability and management control, as the attacker can perform administrative actions without prior authentication.
Remediation
Immediate Action: Contact the vendor, DB Elettronica Telecomunicazioni SpA, to obtain the latest firmware updates. If a specific patch is not yet available, restrict network access to the transmitter management interface to trusted administrative subnets only.
Proactive Monitoring: Review system logs for unauthorized access attempts or unexpected configuration reset commands originating from unknown or suspicious IP addresses.
Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall or an access control list to block unauthorized requests to the /system/api/deviceManagement.cgx endpoint.
Exploitation status
Public Exploit Available: Yes, a proof of concept exploit script is available on ExploitDB (EDB-ID: 51459).
Analyst recommendation
Due to the availability of public exploit code and the critical nature of the device configuration, administrators must treat this vulnerability with high urgency. Immediately isolate the management interface of the affected SFT DAB 600/C units from public or untrusted networks and apply vendor-supplied firmware updates as soon as they become available.
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- ExploitDB-51459 Exploit / PoC
- DB Elettronica Telecomunicazioni Product Homepage
- SFT DAB Series Product Page
- Zero Science Lab Disclosure (ZSL-2022-5775) Third-party advisory
- VulnCheck Advisory: Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Reset Board Config Third-party advisory