Photo Sharing Plus
by Sony
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-16593 | Hig | 0.57 | 8.8 | 0.01 | Jun 19, 2019 | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection. | ||
| CVE-2018-16594 | Hig | 0.53 | 8.1 | 0.01 | Jun 19, 2019 | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal. | ||
| CVE-2019-11336 | Hig | 0.53 | 8.1 | 0.03 | May 14, 2019 | Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a different vulnerability than CVE-2019-10886. | ||
| CVE-2018-16595 | Med | 0.42 | 6.5 | 0.01 | Jun 19, 2019 | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices has a Buffer Overflow. | ||
| CVE-2019-10886 | Med | 0.39 | 5.9 | 0.03 | Apr 19, 2019 | An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other applicable TVs). This vulnerability allows an attacker to read arbitrary files without authentication over HTTP when Photo Sharing… |
- risk 0.57cvss 8.8epss 0.01
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.
- risk 0.53cvss 8.1epss 0.01
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.
- risk 0.53cvss 8.1epss 0.03
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a different vulnerability than CVE-2019-10886.
- risk 0.42cvss 6.5epss 0.01
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices has a Buffer Overflow.
- risk 0.39cvss 5.9epss 0.03
An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other applicable TVs). This vulnerability allows an attacker to read arbitrary files without authentication over HTTP when Photo Sharing…