CVE-2023-7328 PUBLISHED

Screen SFT DAB 600/C <= 1.9.3 Unauthenticated Information Disclosure

Assigner: VulnCheck
Reserved: 12.11.2025 Published: 14.11.2025 Updated: 18.11.2025

Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor DB Elettronica Telecomunicazioni SpA
Product Screen SFT DAB 600/C
Versions Default: unknown
  • affected from 0 to 1.9.3 (incl.)

Credits

  • Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE

Impacts

  • CAPEC-36 Using Unpublished Interfaces or Functionality