CVE-2020-5589
Last modified
CVE-2020-5589 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with firmware versions prior to 4.5.2 have vulnerability that someone within the Bluetooth range can make the Bluetooth pairing and operate such as changing volume of the product.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with firmware versions prior to 4.5.2 have vulnerability that someone within the Bluetooth range can make the Bluetooth pairing and operate such as changing volume of the product.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sony | Wf-1000x Firmware | All versions |
| Sony | Wf-Sp700n Firmware | All versions |
| Sony | Wh-1000xm2 Firmware | All versions |
| Sony | Wh-1000xm3 Firmware | All versions |
| Sony | Wh-Ch700n Firmware | All versions |
| Sony | Wh-H900n Firmware | All versions |
| Sony | Wh-Xb700 Firmware | All versions |
| Sony | Wh-Xb900n Firmware | All versions |
| Sony | Wi-1000x Firmware | All versions |
| Sony | Wi-C600n Firmware | All versions |
| Sony | Wi-Sp600n Firmware | All versions |
References
- https://jvn.jp/en/jp/JVN67447798/Third Party Advisory
- https://jvn.jp/en/jp/JVN67447798/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5589?
How severe is CVE-2020-5589?
How do I fix CVE-2020-5589?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-5583Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated att…6.5
- CVE-2020-5584Cybozu Garoon 4.0.0 to 5.0.1 allow remote attackers to obtai…7.5
- CVE-2020-5585Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to…4.8
- CVE-2020-5586Cross-site scripting vulnerability in Cybozu Garoon 4.10.3 t…4.8
- CVE-2020-5587Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated atta…6.5
- CVE-2020-5588Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1…4.9
- CVE-2020-5590Directory traversal vulnerability in EC-CUBE 3.0.0 to 3.0.18…8.1
- CVE-2020-5591XACK DNS 1.11.0 to 1.11.4, 1.10.0 to 1.10.8, 1.8.0 to 1.8.23…7.5
- CVE-2020-5592Cross-site scripting vulnerability in Zenphoto versions prio…6.1
- CVE-2020-5593Zenphoto versions prior to 1.5.7 allows an attacker to condu…8.8
- CVE-2020-5594Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX series C…9.8
- CVE-2020-5595TCP/IP function included in the firmware of Mitsubishi Elect…9.8
Are you affected by CVE-2020-5589?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
