vendor:
Screen SFT DAB 600/C
by:
LiquidWorm
7.5
CVSS
HIGH
Unauthenticated Information Disclosure
CWE
Product Name: Screen SFT DAB 600/C
Affected Version From: Firmware: 1.9.3, Bios firmware: 7.1 (Apr 19 2021), Gui: 2.46, FPGA: 169.55, uc: 6.15
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Keil-EWEB/2.1, MontaVista® Linux® Carrier Grade eXpress (CGX)
2023
Screen SFT DAB 600/C – Unauthenticated Information Disclosure (userManager.cgx)
Screen is affected by an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this, via a specially crafted request to gain access to sensitive information including usernames and source IP addresses.
Mitigation:
Vendor has not provided any patch or mitigation information.