Vulnerability Description
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backdoor API command, a different vulnerability than CVE-2019-10886.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sony | Photo Sharing Plus | < pkg6.5629 |
| Sony | Kdl-50W800C | - |
| Sony | Kdl-50W805C | - |
| Sony | Kdl-50W807C | - |
| Sony | Kdl-50W809C | - |
| Sony | Kdl-50W820C | - |
| Sony | Kdl-55W800C | - |
| Sony | Kdl-55W805C | - |
| Sony | Kdl-65W850C | - |
| Sony | Kdl-65W855C | - |
| Sony | Kdl-65W857C | - |
| Sony | Kdl-75W850C | - |
| Sony | Kdl-75W855C | - |
| Sony | X7500D | - |
| Sony | Xbr-100Z9D | - |
| Sony | Xbr-43X800D | - |
| Sony | Xbr-43X800E | - |
| Sony | Xbr-43X830C | - |
| Sony | Xbr-49X700D | - |
| Sony | Xbr-49X800C | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/152612/Sony-Smart-TV-Information-DisclosureExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/32ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108072Third Party AdvisoryVDB Entry
- https://seclists.org/bugtraq/2019/Apr/34ExploitMailing ListThird Party Advisory
- https://www.darkmatter.ae/xen1thlabs/sony-smart-tv-photo-sharing-plus-informatioExploitThird Party Advisory
- http://packetstormsecurity.com/files/152612/Sony-Smart-TV-Information-DisclosureExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/32ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108072Third Party AdvisoryVDB Entry
- https://seclists.org/bugtraq/2019/Apr/34ExploitMailing ListThird Party Advisory
- https://www.darkmatter.ae/xen1thlabs/sony-smart-tv-photo-sharing-plus-informatioExploitThird Party Advisory
FAQ
What is CVE-2019-11336?
CVE-2019-11336 is a vulnerability with a CVSS score of 8.1 (HIGH). Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using the Photo Sharing Plus application to execute a backd...
How severe is CVE-2019-11336?
CVE-2019-11336 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11336?
Check the references section above for vendor advisories and patch information. Affected products include: Sony Photo Sharing Plus, Sony Kdl-50W800C, Sony Kdl-50W805C, Sony Kdl-50W807C, Sony Kdl-50W809C.