CVE-2023-33222

When handling contactless cards, usage of a specific function to get additional information from the card which doesn't check the boundary on the data received while reading. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_lite:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:idemia:sigma_lite\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_lite\+:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_extreme:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_wide:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:idemia:morphowave_compact_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_compact:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:idemia:morphowave_xp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_xp:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:idemia:visionpass_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:visionpass:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_sp:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:05

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 6.8
References () https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf - Vendor Advisory () https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf - Vendor Advisory

28 Dec 2023, 14:58

Type Values Removed Values Added
First Time Idemia sigma Extreme
Idemia visionpass Firmware
Idemia morphowave Compact Firmware
Idemia sigma Lite\+ Firmware
Idemia sigma Lite\+
Idemia morphowave Xp
Idemia sigma Extreme Firmware
Idemia sigma Lite Firmware
Idemia sigma Wide
Idemia morphowave Sp Firmware
Idemia morphowave Xp Firmware
Idemia morphowave Sp
Idemia sigma Wide Firmware
Idemia sigma Lite
Idemia morphowave Compact
Idemia
Idemia visionpass
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-787
References () https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf - () https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf - Vendor Advisory
CPE cpe:2.3:h:idemia:sigma_lite:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_xp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:idemia:morphowave_compact_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_xp:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_lite\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_wide:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_sp:-:*:*:*:*:*:*:*
cpe:2.3:h:idemia:morphowave_compact:-:*:*:*:*:*:*:*
cpe:2.3:h:idemia:visionpass:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:visionpass_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_lite\+:-:*:*:*:*:*:*:*
cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:idemia:sigma_extreme:-:*:*:*:*:*:*:*

15 Dec 2023, 13:41

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-15 12:15

Updated : 2024-11-21 08:05


NVD link : CVE-2023-33222

Mitre link : CVE-2023-33222

CVE.ORG link : CVE-2023-33222


JSON object : View

Products Affected

idemia

  • morphowave_sp_firmware
  • visionpass_firmware
  • sigma_wide_firmware
  • morphowave_sp
  • sigma_lite\+
  • sigma_lite\+_firmware
  • sigma_extreme_firmware
  • morphowave_compact_firmware
  • sigma_lite
  • morphowave_compact
  • sigma_extreme
  • morphowave_xp
  • visionpass
  • sigma_wide
  • morphowave_xp_firmware
  • sigma_lite_firmware
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write