CRITICAL
Eibiz i-Media Server Digital Signage 3.8.0 Unauthenticated Privilege Escalation
Published Dec 10, 2025
9.3
CRITICALCVSS 4.0
EPSS 1.05%
Description
Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can exploit the /messagebroker/amf endpoint to elevate privileges and take over user accounts by manipulating role settings without authentication.
Affected products
-
Affected
- ≥ 0, ≤ 3.8.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| EIBIZ Co.,Ltd. | i-Media Server Digital Signage | unaffected | Affected
|
- 3.8.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://www.eibiz.co.th technical-descriptionBroken Link
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30840 Advisory
- https://www.exploit-db.com/exploits/48774 exploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/eibiz-i-media-server-digital-signage-unauthenticated-privilege-escalation third-party-advisoryThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5584.php exploitvendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.eibiz.co.th | technical-descriptionBroken Link | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30840 | Advisory | |
| https://www.exploit-db.com/exploits/48774 | exploitThird Party AdvisoryVDB Entry | |
| https://www.vulncheck.com/advisories/eibiz-i-media-server-digital-signage-unauthenticated-privilege-escalation | third-party-advisoryThird Party Advisory | |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5584.php | exploitvendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Dec 10, 2025
Updated Oct 1, 2026
Reserved Dec 9, 2025
Link CVE-2020-36892
CISA Vulnrichment
Updated Dec 11, 2025
Red Hat
No data
GitHub
No data