CVE-2026-18283

⚪ Do wiadomości

Obejście autoryzacji w Sony XAV-9500ES umożliwia atakującym dostęp do systemu bez uwierzytelnienia.

CVSS
2.4
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system. Was ZDI-CAN-28992.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS2.4
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-08-20 17:17:24 UTC
Ostatnia modyfikacja (NVD)2026-08-21 21:16:55 UTC
Referencje