DB Elettronica Telecomunicazioni SFT DAB 600/C
cpe:2.3:h:dbbroadcast:sft_dab_600/c:*:*:*:*:*:*:*, +3 more
- 1.9.3
This vulnerability is being actively exploited in the wild.
An authentication bypass vulnerability has been identified in the DB Elettronica SFT DAB series transmitters, specifically in version 1.9.3. This vulnerability arises from weak session management that allows attackers to reuse IP-bound session identifiers. By exploiting this flaw, attackers can send unauthorized requests to the device management API, potentially manipulating critical functions of the transmitter.
Exploitation of this vulnerability could lead to unauthorized access and manipulation of the transmitter's configuration and operations, as well as a potential denial-of-service condition.
To reproduce this vulnerability, an attacker must be on the same network as the target device and reuse the IP address of a legitimate user to take advantage of the session binding mechanism. Once the session is established, unauthorized requests can be sent to the device management API to perform critical operations on the transmitter.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.