iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against user accounts.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2020-37228 is a critical authentication bypass vulnerability in iDS6 DSSPro Digital Signage System 6.2 that allows attackers to circumvent CAPTCHA protections designed to prevent automated account compromise. By exploiting the autoLoginVerifyCode object, threat actors can retrieve valid CAPTCHA codes directly from the login endpoint, effectively neutralizing a key defense mechanism against brute-force attacks. This vulnerability affects organizations deploying DSSPro for digital signage management, exposing user accounts to credential-based compromise with a CVSS score of 9.8, indicating severe impact to confidentiality, integrity, and availability of affected systems.
While this CVE lacks direct MITRE ATT&CK technique mapping, Casky's 754 security skills enable detection of the underlying attack patterns through Claude's extended reasoning capabilities. Practitioners would observe findings aligned with Credential Access techniques—specifically T1110 (Brute Force) and T1056 (Input Capture)—as attackers leverage the exposed CAPTCHA retrieval mechanism to automate credential guessing. Casky's skill set would identify suspicious patterns such as repeated authentication attempts from single sources, anomalous login endpoint queries requesting verification codes, and failed login sequences preceding successful account access. Security teams using Casky would flag the abuse of the autoLoginVerifyCode parameter as an indicator of exploitation, enabling them to detect lateral movement and account takeover attempts before attackers establish persistent access to signage infrastructure.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2020-37228. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation