Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pffp-qx9q-h7v4

Опубликовано: 15 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values.

Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values.

EPSS

Процентиль: 20%
0.00061
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values.

EPSS

Процентиль: 20%
0.00061
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-306