ZDI-24-878: Sony XAV-AX5500 Insufficient Verification of Data Authenticity Remote Code Execution Vulnerability
Published Jun 21, 2024
·Updated
This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2024-23922.
Affected Software
1 affected component
Sony XAV-AX5500
Event History
Jun 21, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-878?
The severity of ZDI-24-878 is rated at 6.8 according to CVSS.
2
What type of devices are affected by ZDI-24-878?
ZDI-24-878 affects Sony XAV-AX5500 devices.
3
Can ZDI-24-878 be exploited without authentication?
Yes, ZDI-24-878 can be exploited without requiring authentication.
4
What can attackers do by exploiting ZDI-24-878?
Attackers can execute arbitrary code on affected installations of Sony XAV-AX5500 devices.
5
Is physical access required to exploit ZDI-24-878?
Yes, ZDI-24-878 requires attackers to be physically present to exploit the vulnerability.