MEDIUM · 6.8

CVE-2023-33221

When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that co...

Vulnerability Description

When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is especially problematic if you use Default DESFire key.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IdemiaSigma Lite Firmware< 4.15.5
IdemiaSigma Lite-
IdemiaSigma Lite\+ Firmware< 4.15.5
IdemiaSigma Lite\+-
IdemiaSigma Extreme Firmware< 4.15.5
IdemiaSigma Extreme-
IdemiaSigma Wide Firmware< 4.15.5
IdemiaSigma Wide-
IdemiaMorphowave Compact Firmware< 2.12.2
IdemiaMorphowave Compact-
IdemiaMorphowave Xp Firmware< 2.12.2
IdemiaMorphowave Xp-
IdemiaVisionpass Firmware< 2.12.2
IdemiaVisionpass-
IdemiaMorphowave Sp Firmware< 1.2.7
IdemiaMorphowave Sp-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-33221?

CVE-2023-33221 is a vulnerability with a CVSS score of 6.8 (MEDIUM). When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that co...

How severe is CVE-2023-33221?

CVE-2023-33221 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-33221?

Check the references section above for vendor advisories and patch information. Affected products include: Idemia Sigma Lite Firmware, Idemia Sigma Lite, Idemia Sigma Lite\+ Firmware, Idemia Sigma Lite\+, Idemia Sigma Extreme Firmware.