CyberRota Analysis
AI-GeneratedThe vulnerability in Sony XAV-9500ES devices allows physical attackers to bypass authorization controls through manipulated USB devices, exploiting flaws in the udev rules. This could enable unauthorized access to restricted device functionalities without requiring authentication. Organizations using these devices should prioritize addressing this vulnerability to mitigate potential physical security risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system. Was ZDI-CAN-28992.