CVE-2020-5589
moderate-risk
Published 2020-06-09
SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with firmware versions prior to 4.5.2 have vulnerability that someone within the Bluetooth range can make the Bluetooth pairing and operate such as changing volume of the product.
Do I need to act?
-
0.12% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
ADJACENT_NETWORK
/ LOW complexity
Affected Products (11)
Wf-1000X Firmware
Wf-Sp700N Firmware
Wh-1000Xm2 Firmware
Wh-1000Xm3 Firmware
Wh-Ch700N Firmware
Wh-H900N Firmware
Wh-Xb700 Firmware
Wh-Xb900N Firmware
Wi-1000X Firmware
Wi-C600N Firmware
Wi-Sp600N Firmware
Affected Vendors
References (4)
Third Party Advisory
https://jvn.jp/en/jp/JVN67447798/
Vendor Advisory
https://www.sony.com/electronics/support/audio-video-headphones
Third Party Advisory
https://jvn.jp/en/jp/JVN67447798/
Vendor Advisory
https://www.sony.com/electronics/support/audio-video-headphones
43
/ 100
moderate-risk
Severity
27/34 · High
Exploitability
0/34 · Minimal
Exposure
16/34 · Moderate