CVE-2023-33383

Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:shelly:pro_4pm_firmware:0.11.0:*:*:*:*:*:*:*
cpe:2.3:h:shelly:pro_4pm:-:*:*:*:*:*:*:*

History

09 Aug 2023, 15:28

Type Values Removed Values Added
References (MISC) http://packetstormsecurity.com/files/173954/Shelly-PRO-4PM-0.11.0-Authentication-Bypass.html - (MISC) http://packetstormsecurity.com/files/173954/Shelly-PRO-4PM-0.11.0-Authentication-Bypass.html - Exploit, Third Party Advisory, VDB Entry
References (MISC) https://www.exploitsecurity.io/post/cve-2023-33383-authentication-bypass-via-an-out-of-bounds-read-vulnerability - (MISC) https://www.exploitsecurity.io/post/cve-2023-33383-authentication-bypass-via-an-out-of-bounds-read-vulnerability - Exploit, Third Party Advisory
CPE cpe:2.3:h:shelly:pro_4pm:-:*:*:*:*:*:*:*
cpe:2.3:o:shelly:pro_4pm_firmware:0.11.0:*:*:*:*:*:*:*
First Time Shelly pro 4pm
Shelly
Shelly pro 4pm Firmware
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-125

04 Aug 2023, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/173954/Shelly-PRO-4PM-0.11.0-Authentication-Bypass.html -

02 Aug 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-02 14:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-33383

Mitre link : CVE-2023-33383

CVE.ORG link : CVE-2023-33383


JSON object : View

Products Affected

shelly

  • pro_4pm_firmware
  • pro_4pm
CWE
CWE-125

Out-of-bounds Read