CVE-2024-23922: (Pwn2Own) Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of software updates. The issue results from the lack of proper validation of software update packages. An attacker can leverage this vulnerability to execute code in the context of the device.
Was ZDI-CAN-22939
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23922?
CVE-2024-23922 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-23922?
To fix CVE-2024-23922, update the firmware of the Sony XAV-AX5500 device to the latest version.
Who is affected by CVE-2024-23922?
CVE-2024-23922 affects users of the Sony XAV-AX5500 device running firmware version 1.13.
Can CVE-2024-23922 be exploited remotely?
CVE-2024-23922 requires physical access to the device for exploitation.
What type of vulnerability is CVE-2024-23922?
CVE-2024-23922 is an insufficient firmware update validation vulnerability that allows remote code execution.