vendor:
BRAVIA Digital Signage
by:
LiquidWorm
6.4
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: BRAVIA Digital Signage
Affected Version From: <=1.7.8
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: a:sony:bravia_digital_signage:1.7.8
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows Server 2012 R2, Ubuntu, NodeJS, Express
2020
Sony BRAVIA Digital Signage 1.7.8 – System API Information Disclosure
Sony's BRAVIA Signage is an application to deliver video and still images to Pro BRAVIAs and manage the information via a network. The application is vulnerable to sensitive information disclosure vulnerability. An unauthenticated attacker can visit several API endpoints and disclose information running on the device.
Mitigation:
Ensure that the application is updated to the latest version and that all API endpoints are properly secured.