CVE-2018-16593: OS Command Injection
Published Jun 19, 2019
·Updated
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.
Affected Software
105 affected components
Sony R5c Firmware<8.590
Sony Kdl-32r500c
Sony Kdl-32r503c
Sony Kdl-32r505c
Sony Kdl-40r550c
Sony Kdl-40r553c
Sony Kdl-40r555c
Sony Kdl-48r550c
Sony Kdl-48r553c
Sony Kdl-48r555c
Sony Wd75 Firmware<8.216
Sony Kdl-32wd750
Sony Kdl-32wd751
Sony Kdl-32wd752
Sony Kdl-32wd753
Sony Kdl-32wd754
Sony Kdl-32wd755
Sony Kdl-32wd756
Sony Kdl-32wd757
Sony Kdl-32wd758
Sony Kdl-32wd759
Sony Kdl-43wd750
Sony Kdl-43wd751
Sony Kdl-43wd752
Sony Kdl-43wd753
Sony Kdl-43wd754
Sony Kdl-43wd755
Sony Kdl-43wd756
Sony Kdl-43wd757
Sony Kdl-43wd758
Sony Kdl-43wd759
Sony Kdl-49wd750
Sony Kdl-49wd751
Sony Kdl-49wd752
Sony Kdl-49wd753
Sony Kdl-49wd754
Sony Kdl-49wd755
Sony Kdl-49wd756
Sony Kdl-49wd757
Sony Kdl-49wd758
Sony Kdl-49wd759
Sony Wd65 Firmware<8.216
Sony Kdl-40wd650
Sony Kdl-40wd653
Sony Kdl-40wd655
Sony Kdl-48wd650
Sony Kdl-48wd653
Sony Kdl-48wd655
Sony Xe70 Firmware<8.764
Sony Kd-43xe7000
Sony Kd-43xe7002
Sony Kd-43xe7003
Sony Kd-43xe7004
Sony Kd-43xe7005
Sony Kd-43xe7073
Sony Kd-43xe7077
Sony Kd-43xe7093
Sony Kd-43xe7096
Sony Kd-49xe7000
Sony Kd-49xe7002
Sony Kd-49xe7003
Sony Kd-49xe7004
Sony Kd-49xe7005
Sony Kd-49xe7073
Sony Kd-49xe7077
Sony Kd-49xe7093
Sony Kd-49xe7096
Sony Kd-55xe7000
Sony Kd-55xe7002
Sony Kd-55xe7003
Sony Kd-55xe7004
Sony Kd-55xe7005
Sony Kd-55xe7073
Sony Kd-55xe7077
Sony Kd-55xe7093
Sony Kd-55xe7096
Sony Kd-65xe7002
Sony Kd-65xe7003
Sony Kd-65xe7004
Sony Kd-65xe7005
Sony Kd-65xe7093
Sony Kd-65xe7096
Sony Xf70 Firmware<8.764
Sony Xf70
Sony We75 Firmware<8.464
Sony Kdl-43we750
Sony Kdl-43we753
Sony Kdl-43we754
Sony Kdl-43we755
Sony Kdl-49we750
Sony Kdl-49we753
Sony Kdl-49we754
Sony Kdl-49we755
Sony We6 Firmware<8.464
Sony Kdl-32we610
Sony Kdl-32we613
Sony Kdl-32we615
Sony Kdl-40we660
Sony Kdl-40we663
Sony Kdl-40we665
Sony Kdl-49we660
Sony Kdl-49we663
Sony Kdl-49we665
Sony Wf6 Firmware<8.464
Sony Wf6
Remediation
Patch Available
Event History
Jun 19, 2019
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16593?
CVE-2018-16593 is a vulnerability in the Photo Sharing Plus component on Sony Bravia TV devices that allows Shell Metacharacter Injection.
2
How severe is CVE-2018-16593?
CVE-2018-16593 has a severity rating of 8.8, which is considered high.
3
Which devices are affected by CVE-2018-16593?
Sony Bravia TV devices with specific firmware versions, such as R5C, WD75, XE70, XF70, WE75, WE6, and WF6, are affected by CVE-2018-16593.