Bluetooth Authentication Bypass Vulnerability in Sony XAV-AX8500
CVE-2025-5476
8.8HIGH
What is CVE-2025-5476?
The Sony XAV-AX8500 Bluetooth system is vulnerable to an authentication bypass due to improper isolation in L2CAP channel implementation. This flaw allows network-adjacent attackers to exploit the system without requiring authentication. By leveraging this vulnerability, attackers can potentially infiltrate the system, posing significant risks to user privacy and device security. It is essential for users to remain vigilant and monitor for any updates or patches provided by Sony to mitigate this risk.
Affected Version(s)
XAV-AX8500 2.00.01
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published