CVE-2023-53970 HIGH

CVE-2023-53970: Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Reset Board Config

Vendor Db Elettronica Telecomunicazioni Spa
Product Screen SFT DAB 600/C
Weakness CWE-306 · Missing auth
Published December 22, 2025
Last update December 22, 2025

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations by sending crafted POST requests with manipulated session parameters.

Key dates

02Disclosure timeline

December 22, 2025 CVE published
December 22, 2025 Record updated