CVE-2023-53967
EUVD-2023-6022922.12.2025, 22:16
Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password to directly modify the admin account's authentication.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dbbroadcast | sft_dab_600\/c_firmware | 1.9.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References