Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-16595


The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices has a Buffer Overflow.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.5, indicating it requires adjacent network access with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts and availability (service disruption) for affected systems. Impacting 105 products from sony, from sony, from sony and 102 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2019, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2019-06-19T19:15:10.487

Last Modified

2024-11-21T03:53:01.230

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System sony r5c_firmware < 8.590 Yes
Hardware sony kdl-32r500c - No
Hardware sony kdl-32r503c - No
Hardware sony kdl-32r505c - No
Hardware sony kdl-40r550c - No
Hardware sony kdl-40r553c - No
Hardware sony kdl-40r555c - No
Hardware sony kdl-48r550c - No
Hardware sony kdl-48r553c - No
Hardware sony kdl-48r555c - No
Operating System sony wd75_firmware < 8.216 Yes
Hardware sony kdl-32wd750 - No
Hardware sony kdl-32wd751 - No
Hardware sony kdl-32wd752 - No
Hardware sony kdl-32wd753 - No
Hardware sony kdl-32wd754 - No
Hardware sony kdl-32wd755 - No
Hardware sony kdl-32wd756 - No
Hardware sony kdl-32wd757 - No
Hardware sony kdl-32wd758 - No
Hardware sony kdl-32wd759 - No
Hardware sony kdl-43wd750 - No
Hardware sony kdl-43wd751 - No
Hardware sony kdl-43wd752 - No
Hardware sony kdl-43wd753 - No
Hardware sony kdl-43wd754 - No
Hardware sony kdl-43wd755 - No
Hardware sony kdl-43wd756 - No
Hardware sony kdl-43wd757 - No
Hardware sony kdl-43wd758 - No
Hardware sony kdl-43wd759 - No
Hardware sony kdl-49wd750 - No
Hardware sony kdl-49wd751 - No
Hardware sony kdl-49wd752 - No
Hardware sony kdl-49wd753 - No
Hardware sony kdl-49wd754 - No
Hardware sony kdl-49wd755 - No
Hardware sony kdl-49wd756 - No
Hardware sony kdl-49wd757 - No
Hardware sony kdl-49wd758 - No
Hardware sony kdl-49wd759 - No
Operating System sony wd65_firmware < 8.216 Yes
Hardware sony kdl-40wd650 - No
Hardware sony kdl-40wd653 - No
Hardware sony kdl-40wd655 - No
Hardware sony kdl-48wd650 - No
Hardware sony kdl-48wd653 - No
Hardware sony kdl-48wd655 - No
Operating System sony xe70_firmware < 8.764 Yes
Hardware sony kd-43xe7000 - No
Hardware sony kd-43xe7002 - No
Hardware sony kd-43xe7003 - No
Hardware sony kd-43xe7004 - No
Hardware sony kd-43xe7005 - No
Hardware sony kd-43xe7073 - No
Hardware sony kd-43xe7077 - No
Hardware sony kd-43xe7093 - No
Hardware sony kd-43xe7096 - No
Hardware sony kd-49xe7000 - No
Hardware sony kd-49xe7002 - No
Hardware sony kd-49xe7003 - No
Hardware sony kd-49xe7004 - No
Hardware sony kd-49xe7005 - No
Hardware sony kd-49xe7073 - No
Hardware sony kd-49xe7077 - No
Hardware sony kd-49xe7093 - No
Hardware sony kd-49xe7096 - No
Hardware sony kd-55xe7000 - No
Hardware sony kd-55xe7002 - No
Hardware sony kd-55xe7003 - No
Hardware sony kd-55xe7004 - No
Hardware sony kd-55xe7005 - No
Hardware sony kd-55xe7073 - No
Hardware sony kd-55xe7077 - No
Hardware sony kd-55xe7093 - No
Hardware sony kd-55xe7096 - No
Hardware sony kd-65xe7002 - No
Hardware sony kd-65xe7003 - No
Hardware sony kd-65xe7004 - No
Hardware sony kd-65xe7005 - No
Hardware sony kd-65xe7093 - No
Hardware sony kd-65xe7096 - No
Operating System sony xf70_firmware < 8.764 Yes
Hardware sony xf70 - No
Operating System sony we75_firmware < 8.464 Yes
Hardware sony kdl-43we750 - No
Hardware sony kdl-43we753 - No
Hardware sony kdl-43we754 - No
Hardware sony kdl-43we755 - No
Hardware sony kdl-49we750 - No
Hardware sony kdl-49we753 - No
Hardware sony kdl-49we754 - No
Hardware sony kdl-49we755 - No
Operating System sony we6_firmware < 8.464 Yes
Hardware sony kdl-32we610 - No
Hardware sony kdl-32we613 - No
Hardware sony kdl-32we615 - No
Hardware sony kdl-40we660 - No
Hardware sony kdl-40we663 - No
Hardware sony kdl-40we665 - No
Hardware sony kdl-49we660 - No
Hardware sony kdl-49we663 - No
Hardware sony kdl-49we665 - No
Operating System sony wf6_firmware < 8.464 Yes
Hardware sony wf6 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For sony's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.