iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against user accounts.
Metrics
Affected Vendors & Products
References
History
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against user accounts. | |
| Title | iDS6 DSSPro Digital Signage System 6.2 CAPTCHA Security Bypass | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-16T15:25:46.353Z
Reserved: 2026-05-15T13:32:05.022Z
Link: CVE-2020-37228
No data.
Status : Received
Published: 2026-05-16T16:16:18.667
Modified: 2026-05-16T16:16:18.667
Link: CVE-2020-37228
No data.
OpenCVE Enrichment
Updated: 2026-05-16T17:00:13Z