Description
Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints. Attackers can retrieve network interface information, server configurations, and system metadata by sending requests to the exposed system API.
Problem types
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/49187 (ExploitDB-49187)
pro-bravia.sony.net (Sony BRAVIA Digital Signage Official Homepage)
pro-bravia.sony.net/resources/software/bravia-signage/ (BRAVIA Signage Software Resources)
pro.sony/ue_US/products/display-software (Sony Professional Display Software Product Page)
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5610.php (Zero Science Lab Disclosure (ZSL-2020-5610))
packetstorm.news/files/id/160343 (Packet Storm Security Exploit Entry)
cxsecurity.com/issue/WLB-2020120028 (CXSecurity Vulnerability Database)
exchange.xforce.ibmcloud.com/vulnerabilities/192606 (IBM X-Force Vulnerability Exchange)
www.vulncheck.com/...cated-system-api-information-disclosure (VulnCheck Advisory: Sony BRAVIA Digital Signage 1.7.8 Unauthenticated System API Information Disclosure)