Security readout for executives and security teams
Plain-English summary
This flaw affects All-Dynamics Digital Signage System 2.0.2. If an administrator is logged in and visits a malicious page, the attacker may cause the system to create a new global administrator account. That can lead to full control of the signage management system.
Executive priority
Prioritize if this product manages public-facing or business-critical signage. The issue can allow administrative takeover, but requires a logged-in user to interact with malicious content. Treat as high priority where the admin portal is reachable or administrators browse normally from the same session.
Technical view
CVE-2020-36900 is a CWE-352 cross-site request forgery issue in user management for All-Dynamics Digital Signage System 2.0.2 Build 2098 ILP32W. The CVSS 4.0 score is 8.6. The reported impact is unauthorized creation of administrative users due to missing or insufficient request validation.
Likely exposure
Exposure is likely limited to organizations running the specific affected Digital Signage System 2.0.2 build. Risk increases where the admin interface is reachable by browsers that also access email, internet sites, or other untrusted content.
Exploitation context
A public ExploitDB entry and third-party advisories exist. The source bundle does not indicate CISA KEV listing or confirmed active exploitation. Exploitation requires user interaction by a logged-in user, such as visiting attacker-controlled content.
Researcher notes
The bundle names one affected build and does not provide vendor patch details. Public exploit reference exists, but this assessment does not rely on or reproduce exploit mechanics. Validate scope carefully because the affected list marks other versions as not established in the provided data.
Mitigation direction
- Check All-Dynamics guidance for an update, workaround, or replacement path.
- Restrict access to the administration interface to trusted networks or VPN users.
- Separate signage administration browsing from general web and email use.
- Review administrative accounts and remove any unexpected global administrators.
- Apply compensating controls until vendor-confirmed remediation is available.
Validation and detection
- Identify whether All-Dynamics Digital Signage System 2.0.2 Build 2098 ILP32W is deployed.
- Confirm whether the user-management interface is reachable from untrusted networks.
- Review account creation logs for unexpected administrative users.
- Verify administrators use isolated browsers or workstations for management access.
- Track vendor and advisory sources for remediation status changes.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-352: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2020-36900 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 8.6 (4.0)
- Known Exploited
- No
- Published
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N——Primary CVE scoreVulnerability scoring details
Base CVSS 4.0 score
8.6HighVector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source materials
- CVE List V5 sourceCVE List V5
- ExploitDB-48736CVE reference · exploit
- Zero Science Advisory ID ZSL-2020-5576CVE reference · third-party-advisory
- All-Dynamics Software GmbH HomepageCVE reference · product
- VulnCheck Advisory: All-Dynamics Digital Signage System 2.0.2 Cross-Site Request Forgery via User ManagementCVE reference · third-party-advisory
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Cross-Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
