HIGH
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a different vulnerability than CVE-2019-10886
Published May 14, 2019
8.1
HIGHCVSS 3.0
EPSS 3.21%
Description
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a different vulnerability than CVE-2019-10886.
Affected products
No data.
AND
- < pkg6.5629
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://packetstormsecurity.com/files/152612/Sony-Smart-TV-Information-Disclosure-File-Read.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/32 mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108072 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3017 Advisory
- https://seclists.org/bugtraq/2019/Apr/34 mailing-listx_refsource_BUGTRAQExploitMailing ListThird Party Advisory
- https://www.darkmatter.ae/xen1thlabs/sony-smart-tv-photo-sharing-plus-information-disclosure-vulnerability-xl-19-003/ x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/152612/Sony-Smart-TV-Information-Disclosure-File-Read.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| http://seclists.org/fulldisclosure/2019/Apr/32 | mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory | |
| http://www.securityfocus.com/bid/108072 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3017 | Advisory | |
| https://seclists.org/bugtraq/2019/Apr/34 | mailing-listx_refsource_BUGTRAQExploitMailing ListThird Party Advisory | |
| https://www.darkmatter.ae/xen1thlabs/sony-smart-tv-photo-sharing-plus-information-disclosure-vulnerability-xl-19-003/ | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 14, 2019
Updated Aug 4, 2024
Reserved Apr 18, 2019
Link CVE-2019-11336
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-3017 Assigner mitre
Published May 14, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2019-3017