CVE-2020-36917

7.5

Guangzhou Yeroo Tech Co., Ltd. · iDS6 DSSPro Digital Signage System

The iDS6 DSSPro Digital Signage System is vulnerable to sensitive information disclosure via cleartext cookie transmission, allowing attackers to intercept credentials.

Executive summary

A critical information disclosure vulnerability in the iDS6 DSSPro Digital Signage System allows attackers to intercept user credentials via cleartext communication.

Vulnerability

This vulnerability involves the insecure transmission of sensitive data, specifically authentication credentials, over cleartext HTTP cookies. An unauthenticated attacker can exploit this during man-in-the-middle attacks to capture user passwords processed by the autoSave feature.

Business impact

Successful exploitation allows unauthorized third parties to capture valid administrative or user credentials, leading to full account takeover. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk of unauthorized access to digital signage management interfaces, which could be leveraged to disseminate malicious content or disrupt business operations.

Remediation

Immediate Action: Since no official patch is currently identified for these specific legacy versions, organizations should immediately restrict access to the affected management interfaces to trusted internal networks only. If possible, disable the autoSave feature to prevent the automatic transmission of credentials in cleartext.

Proactive Monitoring: Review network traffic logs for suspicious man-in-the-middle activity or unusual patterns originating from the signage system. Monitor authentication logs for unauthorized access attempts that may indicate credential reuse.

Compensating Controls: Implement a Web Application Firewall (WAF) to inspect traffic for sensitive data leakage or unauthorized access attempts. Enforce mandatory HTTPS throughout the environment to prevent cleartext transmission of session cookies.

Exploitation status

Public Exploit Available: Yes, a technical write-up detailing the vulnerability and exploitation mechanism exists at the referenced Packet Storm Security file.

Analyst recommendation

The severity of this vulnerability, combined with the lack of a vendor-supplied patch, necessitates immediate containment actions. Administrators must prioritize isolating the affected systems from public-facing networks and implementing strict access controls to prevent credential interception. Given the potential for total account compromise, transitioning to a more secure and supported signage solution is strongly advised.

More Guangzhou Yeroo Tech Co., Ltd. CVEs

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.