vendor:
iDS6 Software's DSSPro network digital signage management system
by:
LiquidWorm
7.5
CVSS
HIGH
CAPTCHA Security Bypass
287
CWE
Product Name: iDS6 Software's DSSPro network digital signage management system
Affected Version From: V6.2 B2014.12.12.1220
Affected Version To: V4.3
Patch Exists: NO
Related CWE: N/A
CPE: //a:yerootech:ids6_dsspro_digital_signage_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows XP, Microsoft Windows 7, Microsfot Windows Server 2008, Microsoft Windows Server 2012, Microsoft Windows 10, Apache Tomcat/8.0.44, Apache Tomcat/6.0.35, Apache-Coyote/1.1, Apache Axis/1.4, MySQL 5.5.25, Java 1.8.0
2020
iDS6 DSSPro Digital Signage System 6.2 – CAPTCHA Security Bypass
The CAPTCHA function for DSSPro is prone to a security bypass vulnerability that occurs in the CAPTCHA authentication routine. By requesting the autoLoginVerifyCode object an attacker can receive a JSON message code and successfully bypass the CAPTCHA-based authentication challenge and perform brute-force attacks.
Mitigation:
Ensure that CAPTCHA authentication is properly implemented and configured to prevent brute-force attacks.