CVE-2019-10886
Last modified
CVE-2019-10886 is a vulnerability of currently unknown severity. An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other applicable TVs). This vulnerability allows an attacker to read arbitrary files without authentication over HTTP when Photo Sharing Plus application is running. EPSS estimates a 2.97% chance of exploitation in the next 30 days.
Description
An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other applicable TVs). This vulnerability allows an attacker to read arbitrary files without authentication over HTTP when Photo Sharing Plus application is running. This may allow an attacker to browse a particular directory (e.g. images) inside the private network.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sony | Photo Sharing Plus | < pkg6.5629 |
References
- http://packetstormsecurity.com/files/152612/Sony-Smart-TV-Information-Disclosure-File-Read.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/32Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108072Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2019/Apr/34Exploit, Mailing List, Third Party Advisory
- https://www.sony.com/electronics/support/downloads/00016043Exploit, Vendor Advisory
- http://packetstormsecurity.com/files/152612/Sony-Smart-TV-Information-Disclosure-File-Read.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/32Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108072Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2019/Apr/34Exploit, Mailing List, Third Party Advisory
- https://www.sony.com/electronics/support/downloads/00016043Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10886?
How severe is CVE-2019-10886?
How do I fix CVE-2019-10886?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-10880Within multiple XEROX products a vulnerability allows remote…9.8
- CVE-2019-10881Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030…9.8
- CVE-2019-10882The Netskope client service, v57 before 57.2.0.219 and v60 b…7.8
- CVE-2019-10883Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-W…
- CVE-2019-10884Uniqkey Password Manager 1.14 contains a vulnerability becau…
- CVE-2019-10885An issue was discovered in Ivanti Workspace Control before 1…
- CVE-2019-10887A reflected HTML injection vulnerability on Salicru SLC-20-c…6.1
- CVE-2019-10888A CSRF Issue that can add an admin user was discovered in UK…
- CVE-2019-1089An elevation of privilege vulnerability exists in rpcss.dll …
- CVE-2019-10891An issue was discovered in D-Link DIR-806 devices. There is …9.8
- CVE-2019-10892An issue was discovered in D-Link DIR-806 devices. There is …
- CVE-2019-10893CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Fr…
Are you affected by CVE-2019-10886?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
