Advisories

Screen SFT DAB 1.9.3 Authentication Bypass via IP Session Management

Go Back
severity
high
date
Affecting
  • Firmware: 1.9.3

  • Bios firmware: 7.1 (Apr 19 2021)

  • Gui: 2.46

  • FPGA: 169.55

  • uc: 6.15

CWE
  • CWE-384 Session Fixation
CVSS
7.1
CVSS V4 Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
Description
Screen SFT DAB 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP address-bound session identifiers. Attackers can exploit the vulnerable API by intercepting and reusing established sessions to remove user accounts without proper authorization.