CVE-2023-33220

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
15/12/2023
Last modified:
21/12/2023

Description

<br /> <br /> <br /> <br /> <br /> <br /> <br /> During the retrofit validation process, the firmware doesn&amp;#39;t properly check the boundaries while copying some attributes <br /> to check. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted <br /> device<br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:* 4.15.5 (excluding)
cpe:2.3:h:idemia:sigma_lite:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_lite\+_firmware:*:*:*:*:*:*:*:* 4.15.5 (excluding)
cpe:2.3:h:idemia:sigma_lite\+:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:* 4.15.5 (excluding)
cpe:2.3:h:idemia:sigma_extreme:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:* 4.15.5 (excluding)
cpe:2.3:h:idemia:sigma_wide:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_compact_firmware:*:*:*:*:*:*:*:* 2.12.2 (excluding)
cpe:2.3:h:idemia:morphowave_compact:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_xp_firmware:*:*:*:*:*:*:*:* 2.12.2 (excluding)
cpe:2.3:h:idemia:morphowave_xp:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:visionpass_firmware:*:*:*:*:*:*:*:* 2.12.2 (excluding)
cpe:2.3:h:idemia:visionpass:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:* 1.2.7 (excluding)