CVE-2020-36922

S

ony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints. Attackers can retrieve network interface information, server configurations, and system metadata by sending requests to the exposed system API.

Configurations

Configuration 1 (hide)

cpe:2.3:a:sony:bravia_signage:*:*:*:*:*:*:*:*

History

22 Jan 2026, 21:20

Type Values Removed Values Added
First Time Sony
Sony bravia Signage
CPE cpe:2.3:a:sony:bravia_signage:*:*:*:*:*:*:*:*
References () https://cxsecurity.com/issue/WLB-2020120028 - () https://cxsecurity.com/issue/WLB-2020120028 - Third Party Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/192606 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/192606 - Third Party Advisory
References () https://packetstorm.news/files/id/160343 - () https://packetstorm.news/files/id/160343 - Third Party Advisory
References () https://pro-bravia.sony.net - () https://pro-bravia.sony.net - Product
References () https://pro-bravia.sony.net/resources/software/bravia-signage/ - () https://pro-bravia.sony.net/resources/software/bravia-signage/ - Product
References () https://pro.sony/ue_US/products/display-software - () https://pro.sony/ue_US/products/display-software - Product
References () https://www.exploit-db.com/exploits/49187 - () https://www.exploit-db.com/exploits/49187 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/sony-bravia-digital-signage-unauthenticated-system-api-information-disclosure - () https://www.vulncheck.com/advisories/sony-bravia-digital-signage-unauthenticated-system-api-information-disclosure - Third Party Advisory
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5610.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5610.php - Exploit, Third Party Advisory

06 Jan 2026, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-06 16:15

Updated : 2026-01-22 21:20


NVD link : CVE-2020-36922

Mitre link : CVE-2020-36922

CVE.ORG link : CVE-2020-36922


JSON object : View

Products Affected
CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere