First published: Thu Mar 23 2017(Updated: )
The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, which makes it easier for remote attackers to obtain sensitive information or bypass authentication via a brute-force attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung NT14U | =t-nt14uakucb-1008.0 | |
Samsung NT14U | ||
Samsung X14J eu | =t-ms14jakucb-1102.5 | |
Samsung X14J us | ||
Samsung X14H us | =t-mst14dcncb-1010.0 | |
Samsung X14H firmware | ||
Samsung X12 us | =t-mst12akucb-1114.0 | |
Samsung X12 | ||
Samsung X10P Firmware | =t-mst10pibrcb-1104.0 | |
Samsung X10P eu | ||
Samsung NT14U | =t-nt14udeucb-1007.1 | |
Samsung NT14U | ||
Samsung NT14U | =t-nt14udcncb-1003.1 | |
Samsung NT14U | ||
Samsung X14J eu | =t-ms14jdeucb-1018.0 | |
Samsung X14J eu | ||
Samsung X14J eu | =t-ms14jdcncb-1004.2 | |
Samsung X14J cn | ||
Samsung X14H us | =t-mst14akucb-1100.4 | |
Samsung X14H cn | ||
Samsung X14H us | =t-mst14deucb-1023.0 | |
Samsung X14H cn | ||
Samsung X12 us | =t-mst12deucb-1111.4 | |
Samsung X12 | ||
Samsung X10P Firmware | =t-mst10pauscp-1302.0 | |
Samsung X10P eu | ||
Samsung X10P Firmware | =t-mst10pdeucb-1210.0 | |
Samsung X10P Firmware | ||
Samsung M288OFW firmware | ||
Samsung M288OFW firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5729 has a high severity rating due to the risk of remote attackers executing brute-force attacks on weak WPA2 PSK keys.
To fix CVE-2015-5729, update the firmware of the affected Samsung Smart TVs and printers to the latest version provided by Samsung.
CVE-2015-5729 affects Samsung Smart TVs models X10P, X12, X14H, X14J, NT14U, and Xpress M288OFW printers.
CVE-2015-5729 exploits the generation of weak WPA2 PSK keys in affected Samsung devices, increasing risk of unauthorized access.
Yes, CVE-2015-5729 can be exploited remotely, allowing attackers to bypass authentication and access sensitive information.