Announcements
Security Notices

DWS Vulnerability

3min
feb 15, 2018 update we have released a production os patch for the vulnerabilities outlined below please visit the https //www brightsign biz/downloads/overview page to download the update two vulnerabilities have been found relating to the diagnostic web server (dws) on the device these vulnerabilities are catalogued as cve 2017 17737, 17738, and 17739 cross site scripting attack an attacker can construct a malicious link to content on the dws, which can fool a browser into running arbitrary javascript this may allow an attacker to compromise a brightsign player; however, they would need to know the ip address of the dws to construct the link, and they would need to trick someone who knows the dws login credentials into clicking that link viewable file path a user who already has access to the dws can, by adding certain characters to the /storage html url, view file directories that they should not be able to see so far, it does not seem possible to view or edit the contents of files in this manner—only the directories are visible note we do not recommend using the dws in security sensitive production environments under any circumstance please see the brightsign player security docid\ ecb hwei2wjvvcqlxpd1x for more details