PT-2025-50526 · Unknown · Screen Sft Dab

Published

2025-12-10

·

Updated

2026-01-02

·

CVE-2023-53775

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Screen SFT DAB version 1.9.3
Description Screen SFT DAB 1.9.3 has a flaw in its authentication process, allowing unauthorized modification of user passwords. This is due to weak session management controls, specifically the reuse of IP-bound session identifiers. Attackers can exploit this to issue unauthorized requests to the userManager API and change user credentials without valid authentication. The vulnerability allows attackers to bypass authentication checks.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the userManager API to minimize the risk of exploitation.

Exploit

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2023-53775

Affected Products

Screen Sft Dab