CVE-2020-36922
7.5Sony · BRAVIA Digital Signage
Sony BRAVIA Digital Signage 1.7.8 allows unauthenticated attackers to retrieve sensitive system configuration and network information via exposed API endpoints.
Executive summary
An unauthenticated information disclosure vulnerability in Sony BRAVIA Digital Signage allows remote attackers to access sensitive system metadata and network configurations.
Vulnerability
This vulnerability is an information disclosure flaw (CWE-497) residing in the system API. An unauthenticated attacker can send crafted requests to specific API endpoints to extract sensitive data, including network interface details and server configurations.
Business impact
The exposure of system metadata and network interface information provides attackers with critical reconnaissance data necessary for planning further exploitation. While the CVSS score of 7.5 indicates a high severity, the primary risk involves the unauthorized access to infrastructure details that facilitate lateral movement or targeted attacks against the internal network.
Remediation
Immediate Action: As no official patch is currently identified, restrict network access to the BRAVIA Digital Signage management API to trusted administrative IP addresses only.
Proactive Monitoring: Review web access logs for unauthorized GET requests to API endpoints, specifically monitoring for access patterns directed at /api/system.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an internal firewall policy to block public access to the management ports used by the signage software.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the technical write-up on Exploit Database (EDB-ID: 49187).
Analyst recommendation
Given the availability of public exploitation material and the ease with which sensitive configuration data can be retrieved, this vulnerability poses a significant risk to organizational visibility and security. Administrators should prioritize network isolation of the affected devices and implement strict access controls until the vendor provides a formal resolution.
More Sony CVEs
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- ExploitDB-49187 Exploit / PoC
- Sony BRAVIA Digital Signage Official Homepage
- BRAVIA Signage Software Resources
- Sony Professional Display Software Product Page
- Zero Science Lab Disclosure (ZSL-2020-5610) Third-party advisory
- Packet Storm Security Exploit Entry Exploit / PoC
- CXSecurity Vulnerability Database Exploit / PoC
- IBM X-Force Vulnerability Exchange Vulnerability database entry