Lucene search

K
cveIDEMIACVE-2023-33218
HistoryDec 15, 2023 - 12:15 p.m.

CVE-2023-33218

2023-12-1512:15:43
CWE-787
CWE-121
IDEMIA
web.nvd.nist.gov
10
cve-2023-33218
parameter zone read
parameter zone write
stack buffer overflow
remote code execution
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.002

Percentile

59.5%

The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow.
This could potentially lead to a Remote Code execution on the targeted device.

Affected configurations

Nvd
Node
idemiasigma_lite_firmwareRange<4.15.5
AND
idemiasigma_liteMatch-
Node
idemiasigma_lite\+_firmwareRange<4.15.5
AND
idemiasigma_lite\+Match-
Node
idemiasigma_extreme_firmwareRange<4.15.5
AND
idemiasigma_extremeMatch-
Node
idemiasigma_wide_firmwareRange<4.15.5
AND
idemiasigma_wideMatch-
Node
idemiamorphowave_compact_firmwareRange<2.12.2
AND
idemiamorphowave_compactMatch-
Node
idemiamorphowave_xp_firmwareRange<2.12.2
AND
idemiamorphowave_xpMatch-
Node
idemiavisionpass_firmwareRange<2.12.2
AND
idemiavisionpassMatch-
Node
idemiamorphowave_sp_firmwareRange<1.2.7
AND
idemiamorphowave_spMatch-
VendorProductVersionCPE
idemiasigma_lite_firmware*cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:*
idemiasigma_lite-cpe:2.3:h:idemia:sigma_lite:-:*:*:*:*:*:*:*
idemiasigma_lite\+_firmware*cpe:2.3:o:idemia:sigma_lite\+_firmware:*:*:*:*:*:*:*:*
idemiasigma_lite\+-cpe:2.3:h:idemia:sigma_lite\+:-:*:*:*:*:*:*:*
idemiasigma_extreme_firmware*cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:*
idemiasigma_extreme-cpe:2.3:h:idemia:sigma_extreme:-:*:*:*:*:*:*:*
idemiasigma_wide_firmware*cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:*
idemiasigma_wide-cpe:2.3:h:idemia:sigma_wide:-:*:*:*:*:*:*:*
idemiamorphowave_compact_firmware*cpe:2.3:o:idemia:morphowave_compact_firmware:*:*:*:*:*:*:*:*
idemiamorphowave_compact-cpe:2.3:h:idemia:morphowave_compact:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SIGMA Lite & Lite +",
    "vendor": "IDEMIA",
    "versions": [
      {
        "lessThan": "4.15.5",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "SIGMA Wide",
    "vendor": "IDEMIA",
    "versions": [
      {
        "lessThan": "4.15.5",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "SIGMA Extreme",
    "vendor": "IDEMIA",
    "versions": [
      {
        "lessThan": "4.15.5",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "MorphoWave Compact/XP",
    "vendor": "IDEMIA",
    "versions": [
      {
        "lessThan": "2.12.2",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "VisionPass",
    "vendor": "IDEMIA",
    "versions": [
      {
        "lessThan": "2.12.2",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "MorphoWave SP",
    "vendor": "IDEMIA",
    "versions": [
      {
        "lessThan": "1.2.7",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.002

Percentile

59.5%

Related for CVE-2023-33218