← back
CVE-2020-36923

Sony BRAVIA Digital Signage 1.7.8 Client-Side Protection Bypass via IDOR

CVSS 6.9 MEDIUMEPSS 0.9%CWE-639
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
06 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →