CWE
306
Advisory Published
Updated

CVE-2019-10886

First published: Fri Apr 19 2019(Updated: )

An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other applicable TVs). This vulnerability allows an attacker to read arbitrary files without authentication over HTTP when Photo Sharing Plus application is running. This may allow an attacker to browse a particular directory (e.g. images) inside the private network.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Sony Photo Sharing Plus<pkg6.5629
Sony Kdl-50w800c
Sony Kdl-50w805c
Sony Kdl-50w807c
Sony Kdl-50w809c
Sony Kdl-50w820c
Sony Kdl-55w800c
Sony Kdl-55w805c
Sony Kdl-65w850c
Sony Kdl-65w855c
Sony Kdl-65w857c
Sony Kdl-75w850c
Sony Kdl-75w855c
Sony X7500d
Sony Xbr-100z9d
Sony Xbr-43x800d
Sony Xbr-43x800e
Sony Xbr-43x830c
Sony Xbr-49x700d
Sony Xbr-49x800c
Sony Xbr-49x800d
Sony Xbr-49x800e
Sony Xbr-49x830c
Sony Xbr-49x835c
Sony Xbr-49x835d
Sony Xbr-49x837c
Sony Xbr-49x839c
Sony Xbr-49x900e
Sony Xbr-55a1e
Sony Xbr-55x700d
Sony Xbr-55x800e
Sony Xbr-55x805c
Sony Xbr-55x806e
Sony Xbr-55x807c
Sony Xbr-55x809c
Sony Xbr-55x810c
Sony Xbr-55x850c
Sony Xbr-55x850d
Sony Xbr-55x855c
Sony Xbr-55x855d
Sony Xbr-55x857c
Sony Xbr-55x857d
Sony Xbr-55x900c
Sony Xbr-55x900e
Sony Xbr-55x905c
Sony Xbr-55x907c
Sony Xbr-55x930d
Sony Xbr-55x930e
Sony Xbr-65a1e
Sony Xbr-65x750d
Sony Xbr-65x800c
Sony Xbr-65x805c
Sony Xbr-65x807c
Sony Xbr-65x809c
Sony Xbr-65x810c
Sony Xbr-65x850c
Sony Xbr-65x850d
Sony Xbr-65x850e
Sony Xbr-65x855c
Sony Xbr-65x855d
Sony Xbr-65x857c
Sony Xbr-65x857d
Sony Xbr-65x900c
Sony Xbr-65x900e
Sony Xbr-65x905c
Sony Xbr-65x907c
Sony Xbr-65x930c
Sony Xbr-65x930d
Sony Xbr-65x930e
Sony Xbr-65x935d
Sony Xbr-65x937d
Sony Xbr-65z9d
Sony Xbr-75x850c
Sony Xbr-75x850d
Sony Xbr-75x850e
Sony Xbr-75x855c
Sony Xbr-75x855d
Sony Xbr-75x857d
Sony Xbr-75x900e
Sony Xbr-75x910c
Sony Xbr-75x940c
Sony Xbr-75x940d
Sony Xbr-75x940e
Sony Xbr-75x945c
Sony Xbr-75z9d
Sony Xbr-77a1e
Sony Xbr-85x850d
Sony Xbr-85x855d
Sony Xbr-85x857d

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203