Vulnerability Description
The handler of the retrofit validation command doesn't properly check the boundaries when performing certain validation operations. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Idemia | Sigma Lite Firmware | < 4.15.5 |
| Idemia | Sigma Lite | - |
| Idemia | Sigma Lite\+ Firmware | < 4.15.5 |
| Idemia | Sigma Lite\+ | - |
| Idemia | Sigma Extreme Firmware | < 4.15.5 |
| Idemia | Sigma Extreme | - |
| Idemia | Sigma Wide Firmware | < 4.15.5 |
| Idemia | Sigma Wide | - |
| Idemia | Morphowave Compact Firmware | < 2.12.2 |
| Idemia | Morphowave Compact | - |
| Idemia | Morphowave Xp Firmware | < 2.12.2 |
| Idemia | Morphowave Xp | - |
| Idemia | Visionpass Firmware | < 2.12.2 |
| Idemia | Visionpass | - |
| Idemia | Morphowave Sp Firmware | < 1.2.7 |
| Idemia | Morphowave Sp | - |
Related Weaknesses (CWE)
References
- https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2Vendor Advisory
- https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2Vendor Advisory
FAQ
What is CVE-2023-33219?
CVE-2023-33219 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The handler of the retrofit validation command doesn't properly check the boundaries when performing certain validation operations. This allows a stack-based buffer overflow that could lead to a...
How severe is CVE-2023-33219?
CVE-2023-33219 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-33219?
Check the references section above for vendor advisories and patch information. Affected products include: Idemia Sigma Lite Firmware, Idemia Sigma Lite, Idemia Sigma Lite\+ Firmware, Idemia Sigma Lite\+, Idemia Sigma Extreme Firmware.