Lucene search

K
cveMitreCVE-2019-12477
HistoryJun 07, 2019 - 3:29 p.m.

CVE-2019-12477

2019-06-0715:29:01
CWE-22
mitre
web.nvd.nist.gov
67
supra smart cloud tv
remote file inclusion
openliveurl
fake video
authentication bypass
cve-2019-12477
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.4

Confidence

High

EPSS

0.907

Percentile

98.9%

Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.

Affected configurations

Nvd
Node
suprastv-lc40lt0020f_firmwareMatch-
AND
suprastv-lc40lt0020fMatch-
VendorProductVersionCPE
suprastv-lc40lt0020f_firmware-cpe:2.3:o:supra:stv-lc40lt0020f_firmware:-:*:*:*:*:*:*:*
suprastv-lc40lt0020f-cpe:2.3:h:supra:stv-lc40lt0020f:-:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.4

Confidence

High

EPSS

0.907

Percentile

98.9%