CVE-2020-5589

moderate-risk
Published 2020-06-09

SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP600N with firmware versions prior to 4.5.2 have vulnerability that someone within the Bluetooth range can make the Bluetooth pairing and operate such as changing volume of the product.

Do I need to act?

-
0.12% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10 High
ADJACENT_NETWORK / LOW complexity

Affected Products (11)

Wf-1000X Firmware
Wf-Sp700N Firmware
Wh-1000Xm2 Firmware
Wh-1000Xm3 Firmware
Wh-Ch700N Firmware
Wh-H900N Firmware
Wh-Xb700 Firmware
Wh-Xb900N Firmware
Wi-1000X Firmware
Wi-C600N Firmware
Wi-Sp600N Firmware

Affected Vendors

43
/ 100
moderate-risk
Severity 27/34 · High
Exploitability 0/34 · Minimal
Exposure 16/34 · Moderate