CVE-2023-33218

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
15/12/2023
Last modified:
21/12/2023

Description

<br /> <br /> <br /> The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. <br /> This could potentially lead to a Remote Code execution on the targeted device.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:* 4.15.5 (excluding)
cpe:2.3:h:idemia:sigma_lite:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_lite\+_firmware:*:*:*:*:*:*:*:* 4.15.5 (excluding)
cpe:2.3:h:idemia:sigma_lite\+:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:* 4.15.5 (excluding)
cpe:2.3:h:idemia:sigma_extreme:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:* 4.15.5 (excluding)
cpe:2.3:h:idemia:sigma_wide:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_compact_firmware:*:*:*:*:*:*:*:* 2.12.2 (excluding)
cpe:2.3:h:idemia:morphowave_compact:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_xp_firmware:*:*:*:*:*:*:*:* 2.12.2 (excluding)
cpe:2.3:h:idemia:morphowave_xp:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:visionpass_firmware:*:*:*:*:*:*:*:* 2.12.2 (excluding)
cpe:2.3:h:idemia:visionpass:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:* 1.2.7 (excluding)