CVE-2020-36894
BaseFortify
Publication date: 2025-12-10
Last updated on: 2025-12-17
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| eibiz | i-media_server_digital_signage | 3.8.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Eibiz i-Media Server Digital Signage 3.8.0 allows unauthenticated attackers to bypass authentication by manipulating AMF-encoded objects. Specifically, attackers can send crafted serialized objects to the /messagebroker/amf endpoint, enabling them to create administrative users without proper authentication, effectively bypassing security controls.
How can this vulnerability impact me? :
The vulnerability can have a severe impact as it allows attackers to gain administrative access without authentication. This unauthorized access can lead to full control over the affected system, potentially resulting in data breaches, unauthorized changes, and disruption of services.