8.8
CVE-2020-5589
- EPSS 0.12%
- Veröffentlicht 09.06.2020 08:15:11
- Zuletzt bearbeitet 21.11.2024 05:34:19
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with firmware versions prior to 4.5.2 have vulnerability that someone within the Bluetooth range can make the Bluetooth pairing and operate such as changing volume of the product.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sony ≫ Wf-1000x Firmware Version-
Sony ≫ Wf-sp700n Firmware Version-
Sony ≫ Wh-1000xm2 Firmware Version-
Sony ≫ Wh-1000xm3 Firmware Version-
Sony ≫ Wh-ch700n Firmware Version-
Sony ≫ Wh-h900n Firmware Version-
Sony ≫ Wh-xb700 Firmware Version-
Sony ≫ Wh-xb900n Firmware Version-
Sony ≫ Wi-1000x Firmware Version-
Sony ≫ Wi-c600n Firmware Version-
Sony ≫ Wi-sp600n Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.272 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 8.3 | 6.5 | 10 |
AV:A/AC:L/Au:N/C:C/I:C/A:C
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.