4.3
CVSSv2

CVE-2019-10886

Published: 19/04/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other applicable TVs). This vulnerability allows an malicious user to read arbitrary files without authentication over HTTP when Photo Sharing Plus application is running. This may allow an malicious user to browse a particular directory (e.g. images) inside the private network.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sony photo_sharing_plus

Exploits

Sony Smart TVs suffer from information disclosure and arbitrary file read vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Multiple vulnerabilities in Sony Smart TVs <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: xen1thLabs &lt ...