CVE-2023-53776
BaseFortify
Publication date: 2025-12-10
Last updated on: 2025-12-11
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| screen | sft_dab | 1.9.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-384 | Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The vulnerability can allow attackers to perform unauthorized critical operations on the transmitter by bypassing authentication controls. This could lead to unauthorized access, manipulation, or disruption of the device's functions.
Can you explain this vulnerability to me?
This vulnerability is an authentication bypass in Screen SFT DAB 1.9.3 that exploits weak session management. Attackers can reuse IP-bound session identifiers to bypass authentication and send unauthorized requests to the device management API, allowing them to perform critical operations on the transmitter.