CVE Vulnerabilities

CVE-2023-33684

Published: Jun 06, 2023 | Modified: Feb 16, 2024
CVSS 3.x
5.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Weak session management in DB Elettronica Telecomunicazioni SpA SFT DAB 600/C Firmware: 1.9.3 Bios firmware: 7.1 (Apr 19 2021) Gui: 2.46 FPGA: 169.55 uc: 6.15 allows attackers on the same network to bypass authentication by re-using the IP address assigned to the device by the NAT protocol.

Affected Software

Name Vendor Start Version End Version
Sft_dab_600/c_bios Dbbroadcast 7.1 (including) 7.1 (including)
Sft_dab_600/c_firmware Dbbroadcast 1.9.3 (including) 1.9.3 (including)

References