PT-2021-17682 · Vizio · Vizio E50X-E1+1
Published
2021-08-03
·
Updated
2021-08-11
·
CVE-2021-27942
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Vizio P65-F1 version 6.0.31.4-2
Vizio E50x-E1 version 10.0.31.4-2
Description:
The issue allows a threat actor to execute arbitrary code from a USB drive via the Smart Cast functionality. This is possible because files on the USB drive are effectively under the web root and can be executed.
Recommendations:
For Vizio P65-F1 version 6.0.31.4-2, consider disabling the Smart Cast functionality until a patch is available.
For Vizio E50x-E1 version 10.0.31.4-2, consider disabling the Smart Cast functionality until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vizio E50X-E1
Vizio P65-F1