Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints. Attackers can retrieve network interface information, server configurations, and system metadata by sending requests to the exposed system API.
References
| Link | Resource |
|---|---|
| https://cxsecurity.com/issue/WLB-2020120028 | Third Party Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/192606 | Third Party Advisory |
| https://packetstorm.news/files/id/160343 | Third Party Advisory |
| https://pro-bravia.sony.net | Product |
| https://pro-bravia.sony.net/resources/software/bravia-signage/ | Product |
| https://pro.sony/ue_US/products/display-software | Product |
| https://www.exploit-db.com/exploits/49187 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/sony-bravia-digital-signage-unauthenticated-system-api-information-disclosure | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5610.php | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-01-06 16:15
Updated : 2026-01-22 21:20
NVD link : CVE-2020-36922
Mitre link : CVE-2020-36922
CVE.ORG link : CVE-2020-36922
JSON object : View
Products Affected
sony
- bravia_signage
CWE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
