8.8
CWE
306
Advisory Published
Updated

CVE-2020-5589

First published: Tue Jun 09 2020(Updated: )

SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with firmware versions prior to 4.5.2 have vulnerability that someone within the Bluetooth range can make the Bluetooth pairing and operate such as changing volume of the product.

Credit: vultures@jpcert.or.jp

Affected SoftwareAffected VersionHow to fix
Sony Wf-1000x Firmware
Sony Wf-1000x
Sony Wf-sp700n Firmware
Sony Wf-sp700n
Sony Wh-1000xm2 Firmware
Sony Wh-1000xm2
Sony Wh-1000xm3 Firmware
Sony Wh-1000xm3
Sony Wh-ch700n Firmware
Sony Wh-ch700n
Sony Wh-h900n Firmware
Sony Wh-h900n
Sony Wh-xb700 Firmware
Sony Wh-xb700
Sony Wh-xb900n Firmware
Sony Wh-xb900n
Sony Wi-1000x Firmware
Sony Wi-1000x
Sony Wi-c600n Firmware
Sony Wi-c600n
Sony Wi-sp600n Firmware
Sony Wi-sp600n

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2020-5589?

    CVE-2020-5589 is a vulnerability in SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N, and WI-SP600N with firmware versions prior to 4.5.2.

  • How severe is CVE-2020-5589?

    CVE-2020-5589 has a severity rating of 8.8 (high).

  • What is the impact of CVE-2020-5589?

    CVE-2020-5589 allows someone within Bluetooth range to make Bluetooth pairing and operate the headphones without authorization.

  • Which Sony headphone models are affected by CVE-2020-5589?

    SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N, and WI-SP600N are affected.

  • How can I fix CVE-2020-5589?

    To fix CVE-2020-5589, update the firmware of your SONY wireless headphones to version 4.5.2 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203