Vulnerability Description
Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to conduct a man-in-the-middle attack via a malicous wireless LAN access point. A successful exploitation may result in a malicious file being downloaded/executed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sony | Vaio Update | <= 7.3.0.03150 |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN13555032/index.htmlThird Party Advisory
- https://www.sony.com/electronics/support/articles/00228777Vendor Advisory
- https://jvn.jp/en/jp/JVN13555032/index.htmlThird Party Advisory
- https://www.sony.com/electronics/support/articles/00228777Vendor Advisory
FAQ
What is CVE-2019-5982?
CVE-2019-5982 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to conduct a man-in-the-middle attack via a malicous wireless LAN access point. A succe...
How severe is CVE-2019-5982?
CVE-2019-5982 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5982?
Check the references section above for vendor advisories and patch information. Affected products include: Sony Vaio Update.