PT-2025-47024 · Cscreen · Screen Sft Dab 600/C

Gjoko Krstic

·

Published

2025-11-14

·

Updated

2025-12-26

·

CVE-2023-7328

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Screen SFT DAB 600/C firmware versions up to and including 1.9.3
Description The Screen SFT DAB 600/C firmware has an issue with access control on the user management API. Unauthenticated requests can retrieve structured user data, including account names and connection metadata such as client IP and timeout values. The affected API endpoint is the user management API. The retrieved data includes account names and client IP addresses.
Recommendations Update to a version later than 1.9.3.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-7328

Affected Products

Screen Sft Dab 600/C