CVE-2023-33218

The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This could potentially lead to a Remote Code execution on the targeted device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_lite:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:idemia:sigma_lite\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_lite\+:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_extreme:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_wide:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:idemia:morphowave_compact_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_compact:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:idemia:morphowave_xp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_xp:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:idemia:visionpass_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:visionpass:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_sp:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:05

Type Values Removed Values Added
References () https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf - Vendor Advisory () https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf - Vendor Advisory
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 9.1

21 Dec 2023, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.1
v2 : unknown
v3 : 9.8
CWE CWE-787
CPE cpe:2.3:h:idemia:visionpass:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_compact_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_extreme:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:visionpass_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_xp:-:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_lite\+:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_xp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_lite:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_lite\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_sp:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_compact:-:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_wide:-:*:*:*:*:*:*:*
References () https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf - () https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf - Vendor Advisory
Summary
  • (es) Los controladores de comandos Parameter Zone Read and Parameter Zone Write permiten realizar un desbordamiento del búfer de pila. Potencialmente, esto podría conducir a la ejecución de un código remoto en el dispositivo de destino.
First Time Idemia sigma Lite
Idemia sigma Extreme Firmware
Idemia sigma Extreme
Idemia visionpass Firmware
Idemia sigma Lite Firmware
Idemia morphowave Compact
Idemia morphowave Compact Firmware
Idemia visionpass
Idemia
Idemia sigma Wide Firmware
Idemia sigma Lite\+
Idemia morphowave Xp
Idemia morphowave Sp Firmware
Idemia sigma Wide
Idemia morphowave Sp
Idemia sigma Lite\+ Firmware
Idemia morphowave Xp Firmware

15 Dec 2023, 13:41

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-15 12:15

Updated : 2024-11-21 08:05


NVD link : CVE-2023-33218

Mitre link : CVE-2023-33218

CVE.ORG link : CVE-2023-33218


JSON object : View

Products Affected

idemia

  • sigma_lite\+_firmware
  • morphowave_xp
  • sigma_extreme_firmware
  • visionpass
  • sigma_lite_firmware
  • visionpass_firmware
  • sigma_lite\+
  • sigma_lite
  • sigma_extreme
  • morphowave_compact_firmware
  • morphowave_xp_firmware
  • sigma_wide_firmware
  • sigma_wide
  • morphowave_sp_firmware
  • morphowave_compact
  • morphowave_sp
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write