Remote Code Execution Vulnerability in Sony XAV-AX5500 Devices
CVE-2024-23922

6.8MEDIUM

Key Information:

Vendor

Sony

Vendor
CVE Published:
23 September 2024

What is CVE-2024-23922?

The Sony XAV-AX5500 is susceptible to a vulnerability that allows arbitrary code execution due to inadequate validation of firmware updates. This flaw permits an attacker with physical access to the device to exploit the issue without needing any authentication, potentially putting sensitive data and system integrity at risk. Proper validation of software update packages is essential to mitigate this security concern and protect users from unauthorized code execution.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-23922 : Remote Code Execution Vulnerability in Sony XAV-AX5500 Devices