Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values. | |
| Title | Screen SFT DAB 600/C <= 1.9.3 Unauthenticated Information Disclosure | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-14T22:51:05.202Z
Reserved: 2025-11-12T20:20:51.734Z
Link: CVE-2023-7328
No data.
Status : Received
Published: 2025-11-14T23:15:43.640
Modified: 2025-11-14T23:15:43.640
Link: CVE-2023-7328
No data.
OpenCVE Enrichment
No data.