CVE-2015-5729
Summary
| CVE | CVE-2015-5729 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-03-23 20:59:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, which makes it easier for remote attackers to obtain sensitive information or bypass authentication via a brute-force attack. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-200 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Samsung | M288ofw | - | All | All | All |
| Operating System | Samsung | M288ofw Firmware | - | All | All | All |
| Hardware | Samsung | Nt14u Cn | - | All | All | All |
| Hardware | Samsung | Nt14u Eu | - | All | All | All |
| Operating System | Samsung | Nt14u Firmware | t-nt14uakucb-1008.0 | All | All | All |
| Operating System | Samsung | Nt14u Firmware | t-nt14udcncb-1003.1 | All | All | All |
| Operating System | Samsung | Nt14u Firmware | t-nt14udeucb-1007.1 | All | All | All |
| Hardware | Samsung | Nt14u Us | - | All | All | All |
| Hardware | Samsung | X10p Eu | - | All | All | All |
| Operating System | Samsung | X10p Firmware | t-mst10pauscp-1302.0 | All | All | All |
| Operating System | Samsung | X10p Firmware | t-mst10pdeucb-1210.0 | All | All | All |
| Operating System | Samsung | X10p Firmware | t-mst10pibrcb-1104.0 | All | All | All |
| Hardware | Samsung | X10p Ibr | - | All | All | All |
| Hardware | Samsung | X10p Us | - | All | All | All |
| Hardware | Samsung | X12 Eu | - | All | All | All |
| Operating System | Samsung | X12 Firmware | t-mst12akucb-1114.0 | All | All | All |
| Operating System | Samsung | X12 Firmware | t-mst12deucb-1111.4 | All | All | All |
| Hardware | Samsung | X12 Us | - | All | All | All |
| Hardware | Samsung | X14h Cn | - | All | All | All |
| Hardware | Samsung | X14h Eu | - | All | All | All |
| Operating System | Samsung | X14h Firmware | t-mst14akucb-1100.4 | All | All | All |
| Operating System | Samsung | X14h Firmware | t-mst14dcncb-1010.0 | All | All | All |
| Operating System | Samsung | X14h Firmware | t-mst14deucb-1023.0 | All | All | All |
| Hardware | Samsung | X14h Us | - | All | All | All |
| Hardware | Samsung | X14j Cn | - | All | All | All |
| Hardware | Samsung | X14j Eu | - | All | All | All |
| Operating System | Samsung | X14j Firmware | t-ms14jakucb-1102.5 | All | All | All |
| Operating System | Samsung | X14j Firmware | t-ms14jdcncb-1004.2 | All | All | All |
| Operating System | Samsung | X14j Firmware | t-ms14jdeucb-1018.0 | All | All | All |
| Hardware | Samsung | X14j Us | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Samsung Smart TV SoftAP Lets Remote Users Bypass Security Restrictions on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| KaOtiCo NeUtRaL: Samsung Smarttv and Printers weak password SoftAP wpa2 | af854a3a-2127-422b-91ae-364da2661108 | kaoticoneutral.blogspot.com.ar | Exploit, Technical Description, Third Party Advisory |
| Samsung SoftAP Weak Password ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Full Disclosure: Samsung softap weak random generated password | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Third Party Advisory, VDB Entry |
| Samsung SmartTV and Printers CVE-2015-5729 Weak Password Security Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Samsung Printer SoftAP Weak Default WiFi Key Lets Remote Users Bypass WiFi Security Protections - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.