CVE-2017-2286: Critical severity sony nfc port firmware vulnerability
Untrusted search path vulnerability in NFC Port Software Version 5.5.0.6 and earlier (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S), NFC Port Software Version 5.3.6.7 and earlier (for RC-S320, RC-S310/J1C, RC-S310/ED4C), PC/SC Activator for Type B Ver.1.2.1.0 and earlier, SFCard Viewer 2 Ver.2.5.0.0 and earlier, NFC Net Installer Ver.1.1.0.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2286?
CVE-2017-2286 has been categorized as a medium severity vulnerability due to its potential impact on system security.
How do I fix CVE-2017-2286?
To fix CVE-2017-2286, users should upgrade to NFC Port Software Version 5.5.0.7 or later, or apply the relevant patches provided by Sony.
Which software versions are affected by CVE-2017-2286?
CVE-2017-2286 affects NFC Port Software Version 5.5.0.6 and earlier, along with specific versions of PC/SC Activator for Type B and SFCard Viewer.
What type of vulnerability is CVE-2017-2286?
CVE-2017-2286 is an untrusted search path vulnerability that may allow an attacker to execute arbitrary code.
What devices are impacted by CVE-2017-2286?
Devices impacted by CVE-2017-2286 include various Sony NFC Port firmware versions and models such as RC-S310 and RC-S320.