peter bassill · operator
$ cve CVE-2022-23747 JSON

CVE-2022-23747

9.8
CRITICAL · CVSS 3.1 · EPSS 10.2% (pctl 96)

Patch early

EPSS 10.2% — above the 10% action threshold.

Description

In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.24% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2022-08-17
Last modified2026-06-17

Affected (6)

VendorProduct
sonyxperia 1
sonyxperia 1 firmware
sonyxperia 5
sonyxperia 5 firmware
sonyxperia pro
sonyxperia pro firmware

References

→ the Explorer  ·  watch your stack  ·  NVD