DB Elettronica Telecomunicazioni SFT DAB 600/C
cpe:2.3:h:dbbroadcast:sft_dab_600/c:*:*:*:*:*:*:*, +3 more
- 1.9.3
- 7.1
- 2.46
- 169.55
- 6.15
This vulnerability is being actively exploited in the wild.
A session management vulnerability has been identified in the DB Elettronica SFT DAB series, specifically in version 1.9.3. This vulnerability allows attackers to bypass authentication by reusing session identifiers tied to IP addresses. Exploitation involves intercepting and reusing these session identifiers to access a vulnerable API, enabling unauthorized removal of user accounts.
Exploitation of this vulnerability leads to unauthorized account deletions on the affected device.
To reproduce this vulnerability, an established session must be intercepted and its session identifier reused. This can be done by waiting for a session to be established and then sending unauthorized requests to the vulnerable API endpoint 'userManager.cgx' to remove a user account.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.