DB Elettronica Telecomunicazioni SFT DAB 600/C
cpe:2.3:h:dbbroadcast:sft_dab_600/c:*:*:*:*:*:*:*, +3 more
- 1.9.3
- 7.1
- 2.46
- 169.55
- 6.15
This vulnerability is being actively exploited in the wild.
An authentication bypass vulnerability has been identified in the Screen SFT DAB series DAB transmitters, specifically in version 1.9.3. This vulnerability allows attackers to change user passwords by exploiting weak session management controls. By reusing IP-bound session identifiers, attackers can issue unauthorized requests to the userManager API and modify user credentials without proper authentication.
Exploitation of this vulnerability could lead to unauthorized password changes, allowing for potential unauthorized access to user accounts or privileges.
To reproduce this vulnerability, an attacker must be on the same network as the victim and reuse the victim's IP address to exploit the weak session management. Once the session is established, the attacker can send unauthorized requests to the userManager API to change user passwords.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.