CVE-2020-36923
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
06/01/2026
Last modified:
08/01/2026
Description
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
9.80
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://cxsecurity.com/issue/WLB-2020120031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/192607
- https://packetstormsecurity.com/files/160344
- https://pro-bravia.sony.net
- https://pro-bravia.sony.net/resources/software/bravia-signage/
- https://pro.sony/ue_US/products/display-software
- https://www.vulncheck.com/advisories/sony-bravia-digital-signage-client-side-protection-bypass-via-idor
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5611.php
- https://www.zeroscience.mk/codes/sonybravia_idor.txt
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5611.php



