Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Db Elettronica
Db Elettronica screen Sft Dab 600c |
|
| CPEs | cpe:2.3:a:db_elettronica:screen_sft_dab_600c:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Db Elettronica
Db Elettronica screen Sft Dab 600c |
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dbbroadcast
Dbbroadcast sft Dab 600/c |
|
| Vendors & Products |
Dbbroadcast
Dbbroadcast sft Dab 600/c |
Fri, 14 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values. | |
| Title | Screen SFT DAB 600/C <= 1.9.3 Unauthenticated Information Disclosure | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-18T16:25:16.998Z
Reserved: 2025-11-12T20:20:51.734Z
Link: CVE-2023-7328
Updated: 2025-11-18T16:25:06.942Z
Status : Awaiting Analysis
Published: 2025-11-14T23:15:43.640
Modified: 2025-11-18T17:15:57.660
Link: CVE-2023-7328
No data.