Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-36922. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated information disclosure vulnerability in Sony BRAVIA Digital Signage 1.7.8. It leverages an exposed API endpoint to retrieve sensitive system information, including network interfaces, server time, and OS details.
Description
Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints. Attackers can retrieve network interface information, server configurations, and system metadata by sending requests to the exposed system API.
Exploits (1)
This exploit demonstrates an unauthenticated information disclosure vulnerability in Sony BRAVIA Digital Signage 1.7.8. It leverages an exposed API endpoint to retrieve sensitive system information, including network interfaces, server time, and OS details.
References (9)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N