NIS2 & DORA in force. EU AI Act next — book a demo
CVEnvd16 May 2026

CVE-2020-37228 (CVSS 9.8) — iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retri

CVE. Sourced from nvd, summarised by Matproof.

AI Analysis

What changed and what to do.

A critical vulnerability, CVE-2020-37228, has been published with a CVSS score of 9.8, indicating a severe security flaw in the iDS6 DSSPro Digital Signage System version 6.2. The issue allows an attacker to bypass CAPTCHA authentication by directly requesting the autoLoginVerifyCode object, effectively enabling unauthorized access without valid credentials. This vulnerability was published on May 16, 2026, and is now publicly documented in the National Vulnerability Database.

Organizations affected are primarily those using iDS6 DSSPro for digital signage, which includes sectors such as retail, hospitality, transportation, healthcare, and corporate communications. Any entity relying on this system for public-facing displays or internal information boards is at risk, as the bypass could allow attackers to manipulate content, disrupt operations, or gain a foothold in the network.

Compliance teams should immediately verify if their organization uses iDS6 DSSPro 6.2 and, if so, apply any available patches or vendor-supplied mitigations. Until a fix is deployed, consider isolating the system from untrusted networks and implementing additional access controls, such as network segmentation or multi-factor authentication. Document this vulnerability in your risk register and update your incident response plan to address potential exploitation.

View original at nvd

This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.

More CVE updates

Latest in CVE.

← Back to all updates
Live regulatory monitoring

Never miss a compliance update.

Get weekly digests of DORA, NIS2, GDPR, MaRisk, and ISO 27001 changes — straight to your inbox. Free.

No spam. Weekly digest only. Unsubscribe anytime.

DORANIS2GDPRMaRiskISO 27001

Map this to your controls

Connect regulatory changes to your compliance work.

Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.

Book a DemoBrowse all updates
CVE-2020-37228 (CVSS 9.8) — iDS6 DSSPro Digital Signage S… — CVE | Matproof