Browse all 12 CVE security advisories affecting Sony. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Sony operates primarily in consumer electronics, entertainment, and gaming, with products ranging from PlayStation consoles to media services. Historically, the company's systems have been vulnerable to remote code execution, cross-site scripting, and privilege escalation, often through web interfaces and firmware flaws. Notable incidents include the 2011 PlayStation Network breach exposing 77 million users' data, and multiple vulnerabilities in its cameras and IoT devices. Despite improvements, Sony's current 12 CVEs indicate ongoing security challenges, particularly in firmware and web application components. The company's diverse product ecosystem creates complex attack surfaces, requiring continuous vulnerability management to protect user data and maintain system integrity.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-23922 | Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability — XAV-AX5500CWE-345 | 6.8 | Medium | 2024-09-23 |
| CVE-2024-23972 | Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability — XAV-AX5500CWE-120 | 6.8 | Medium | 2024-09-23 |
| CVE-2024-23934 | Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — XAV-AX5500CWE-121 | 8.8 | High | 2024-09-23 |
| CVE-2024-23933 | Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability — XAV-AX5500CWE-121 | 6.8 | Medium | 2024-09-23 |
This page lists every published CVE security advisory associated with Sony. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.