CVE-2023-53968 CRITICAL

CVE-2023-53968: Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Erase Account

Vendor Db Elettronica Telecomunicazioni Spa
Product Screen SFT DAB 600/C
Weakness CWE-306 · Missing auth
Published December 22, 2025
Last update December 22, 2025

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts without proper authentication.

Key dates

02Disclosure timeline

December 22, 2025 CVE published
December 22, 2025 Record updated