CVE-2023-33248

Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relevant commands via an audio signal between 16 and 22 kHz (often outside the range of human adult hearing). Commands at these frequencies are essentially never spoken by authorized actors, but a substantial fraction of the commands are successful.
References
Link Resource
https://arxiv.org/abs/2305.10358 Third Party Advisory
https://cios2023.org/papers Third Party Advisory
https://github.com/reveondivad/nuance Exploit Third Party Advisory
https://sites.google.com/view/nuitattack/home Third Party Advisory
https://www.usenix.org/system/files/sec23fall-prepub-261-xia-qi.pdf Exploit Technical Description Third Party Advisory
https://youtu.be/3gEc5ZFWIWo Exploit Technical Description Third Party Advisory
https://arxiv.org/abs/2305.10358 Third Party Advisory
https://cios2023.org/papers Third Party Advisory
https://github.com/reveondivad/nuance Exploit Third Party Advisory
https://sites.google.com/view/nuitattack/home Third Party Advisory
https://www.usenix.org/system/files/sec23fall-prepub-261-xia-qi.pdf Exploit Technical Description Third Party Advisory
https://youtu.be/3gEc5ZFWIWo Exploit Technical Description Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:amazon:alexa:8960323972:*:*:*:*:*:*:*
OR cpe:2.3:h:amazon:echo_dot:-:*:2nd_gen:*:*:*:*:*
cpe:2.3:h:amazon:echo_dot:-:*:3rd_gen:*:*:*:*:*

History

21 Nov 2024, 08:05

Type Values Removed Values Added
References () https://arxiv.org/abs/2305.10358 - Third Party Advisory () https://arxiv.org/abs/2305.10358 - Third Party Advisory
References () https://cios2023.org/papers - Third Party Advisory () https://cios2023.org/papers - Third Party Advisory
References () https://github.com/reveondivad/nuance - Exploit, Third Party Advisory () https://github.com/reveondivad/nuance - Exploit, Third Party Advisory
References () https://sites.google.com/view/nuitattack/home - Third Party Advisory () https://sites.google.com/view/nuitattack/home - Third Party Advisory
References () https://www.usenix.org/system/files/sec23fall-prepub-261-xia-qi.pdf - Exploit, Technical Description, Third Party Advisory () https://www.usenix.org/system/files/sec23fall-prepub-261-xia-qi.pdf - Exploit, Technical Description, Third Party Advisory
References () https://youtu.be/3gEc5ZFWIWo - Exploit, Technical Description, Third Party Advisory () https://youtu.be/3gEc5ZFWIWo - Exploit, Technical Description, Third Party Advisory

01 Jun 2023, 17:20

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6
CPE cpe:2.3:o:amazon:alexa:8960323972:*:*:*:*:*:*:*
cpe:2.3:h:amazon:echo_dot:-:*:2nd_gen:*:*:*:*:*
cpe:2.3:h:amazon:echo_dot:-:*:3rd_gen:*:*:*:*:*
References (MISC) https://arxiv.org/abs/2305.10358 - (MISC) https://arxiv.org/abs/2305.10358 - Third Party Advisory
References (MISC) https://github.com/reveondivad/nuance - (MISC) https://github.com/reveondivad/nuance - Exploit, Third Party Advisory
References (MISC) https://sites.google.com/view/nuitattack/home - (MISC) https://sites.google.com/view/nuitattack/home - Third Party Advisory
References (MISC) https://www.usenix.org/system/files/sec23fall-prepub-261-xia-qi.pdf - (MISC) https://www.usenix.org/system/files/sec23fall-prepub-261-xia-qi.pdf - Exploit, Technical Description, Third Party Advisory
References (MISC) https://youtu.be/3gEc5ZFWIWo - (MISC) https://youtu.be/3gEc5ZFWIWo - Exploit, Technical Description, Third Party Advisory
References (MISC) https://cios2023.org/papers - (MISC) https://cios2023.org/papers - Third Party Advisory
First Time Amazon alexa
Amazon
Amazon echo Dot

Information

Published : 2023-05-24 22:15

Updated : 2024-11-21 08:05


NVD link : CVE-2023-33248

Mitre link : CVE-2023-33248

CVE.ORG link : CVE-2023-33248


JSON object : View

Products Affected

amazon

  • alexa
  • echo_dot