← Advisories

Sony BRAVIA Digital Signage 1.7.8 Client-Side Protection Bypass / IDOR

Medium
Advisory ID
ZSL-2020-5611
Release Date
02 December 2020
Vendor
Sony Electronics Inc. - https://pro.sony
Affected Version
<=1.7.8
Tested On
Microsoft Windows Server 2012 R2, Ubuntu, NodeJS, Express
Summary

Sony's BRAVIA Signage is an application to deliver video and still images to Pro BRAVIAs and manage the information via a network. Features include management of displays, power schedule management, content playlists, scheduled delivery management, content interrupt, and more. This cost-effective digital signage management solution is ideal for presenting attractive, informative visual content in retail spaces and hotel reception areas, visitor attractions, educational and corporate environments.

Description

Insecure direct object references occur when an application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access the hidden '/#/content-creation' resource in the system.

Proof of Concept
Disclosure Timeline
20.09.2020Vulnerability discovered.
15.10.2020Submitted to Sony via Hackerone.
20.11.2020Vendor states that the vulnerabilities are just informative and that all the issues are working as intended.
02.12.2020Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
02.12.2020Initial release
17.12.2020Added reference [1], [2] and [3]
24.03.2026Added reference [4]