CVE-2023-37215: JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials
Published Jul 30, 2023
·Updated
JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials
Affected Software
2 affected components
JBL Jbl Bar 5.1 Surround Firmware<23.23.51.00
JBL Jbl Bar 5.1 Surround
Remediation
Information
Update to Version 23.23.51.00
Event History
Jul 30, 2023
CVE Published
via MITRE·08:42 AM
Data Sourced
via MITRE·08:42 AM
RemedyDescriptionSeverityWeakness
Data Sourced
09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37215?
CVE-2023-37215 has been rated as a moderate severity vulnerability due to the use of hard-coded credentials in the JBL soundbar.
2
How do I fix CVE-2023-37215?
To mitigate CVE-2023-37215, it is recommended to update the JBL soundbar firmware to the latest version that addresses hard-coded credentials.
3
Which JBL soundbar models are affected by CVE-2023-37215?
CVE-2023-37215 specifically affects the JBL Bar 5.1 Surround firmware versions prior to 23.23.51.00.
4
What are the implications of CVE-2023-37215?
The implications of CVE-2023-37215 include potential unauthorized access to the device due to hard-coded credentials.
5
Has JBL released any advisory regarding CVE-2023-37215?
Yes, JBL has acknowledged CVE-2023-37215 and provided guidance for affected users to update their firmware.