Back to overview

CVE-2020-37228

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against user accounts.

Metadata

CVE ID
CVE-2020-37228
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-05-15 13:32 UTC
Published
2026-05-16 15:25 UTC
Last updated
2026-05-18 17:53 UTC
Primary CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
Vendor / Product
Yerootech / iDS6 DSSPro Digital Signage System
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Yerootech iDS6 DSSPro Digital Signage System 6.2
Weakness (CWE)
CWESourceDescription
CWE-307 cna Improper Restriction of Excessive Authentication Attempts
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References (4)
Back to overview