CVE-2018-16594: Path Traversal
Published Jun 19, 2019
·Updated
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.
Affected Software
105 affected components
Sony R5c Firmware<8.590
Sony Kdl-32r500c
Sony Kdl-32r503c
Sony Kdl-32r505c
Sony Kdl-40r550c
Sony Kdl-40r553c
Sony Kdl-40r555c
Sony Kdl-48r550c
Sony Kdl-48r553c
Sony Kdl-48r555c
Sony Wd75 Firmware<8.216
Sony Kdl-32wd750
Sony Kdl-32wd751
Sony Kdl-32wd752
Sony Kdl-32wd753
Sony Kdl-32wd754
Sony Kdl-32wd755
Sony Kdl-32wd756
Sony Kdl-32wd757
Sony Kdl-32wd758
Sony Kdl-32wd759
Sony Kdl-43wd750
Sony Kdl-43wd751
Sony Kdl-43wd752
Sony Kdl-43wd753
Sony Kdl-43wd754
Sony Kdl-43wd755
Sony Kdl-43wd756
Sony Kdl-43wd757
Sony Kdl-43wd758
Sony Kdl-43wd759
Sony Kdl-49wd750
Sony Kdl-49wd751
Sony Kdl-49wd752
Sony Kdl-49wd753
Sony Kdl-49wd754
Sony Kdl-49wd755
Sony Kdl-49wd756
Sony Kdl-49wd757
Sony Kdl-49wd758
Sony Kdl-49wd759
Sony Wd65 Firmware<8.216
Sony Kdl-40wd650
Sony Kdl-40wd653
Sony Kdl-40wd655
Sony Kdl-48wd650
Sony Kdl-48wd653
Sony Kdl-48wd655
Sony Xe70 Firmware<8.764
Sony Kd-43xe7000
Sony Kd-43xe7002
Sony Kd-43xe7003
Sony Kd-43xe7004
Sony Kd-43xe7005
Sony Kd-43xe7073
Sony Kd-43xe7077
Sony Kd-43xe7093
Sony Kd-43xe7096
Sony Kd-49xe7000
Sony Kd-49xe7002
Sony Kd-49xe7003
Sony Kd-49xe7004
Sony Kd-49xe7005
Sony Kd-49xe7073
Sony Kd-49xe7077
Sony Kd-49xe7093
Sony Kd-49xe7096
Sony Kd-55xe7000
Sony Kd-55xe7002
Sony Kd-55xe7003
Sony Kd-55xe7004
Sony Kd-55xe7005
Sony Kd-55xe7073
Sony Kd-55xe7077
Sony Kd-55xe7093
Sony Kd-55xe7096
Sony Kd-65xe7002
Sony Kd-65xe7003
Sony Kd-65xe7004
Sony Kd-65xe7005
Sony Kd-65xe7093
Sony Kd-65xe7096
Sony Xf70 Firmware<8.764
Sony Xf70
Sony We75 Firmware<8.464
Sony Kdl-43we750
Sony Kdl-43we753
Sony Kdl-43we754
Sony Kdl-43we755
Sony Kdl-49we750
Sony Kdl-49we753
Sony Kdl-49we754
Sony Kdl-49we755
Sony We6 Firmware<8.464
Sony Kdl-32we610
Sony Kdl-32we613
Sony Kdl-32we615
Sony Kdl-40we660
Sony Kdl-40we663
Sony Kdl-40we665
Sony Kdl-49we660
Sony Kdl-49we663
Sony Kdl-49we665
Sony Wf6 Firmware<8.464
Sony Wf6
Remediation
Patch Available
Event History
Jun 19, 2019
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16594?
CVE-2018-16594 is classified as a high-severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2018-16594?
To mitigate CVE-2018-16594, update the affected Sony Bravia TV firmware to version 8.590 or later.
3
What devices are affected by CVE-2018-16594?
CVE-2018-16594 impacts Sony Bravia TV devices running firmware versions up to 8.587.
4
Can CVE-2018-16594 be exploited remotely?
Yes, CVE-2018-16594 can be exploited remotely, allowing attackers to access restricted files.
5
Is there a workaround for CVE-2018-16594?
There are no specific workarounds for CVE-2018-16594 other than applying the firmware update as soon as possible.