Vulnerability Description
When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is especially problematic if you use Default DESFire key.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Idemia | Sigma Lite Firmware | < 4.15.5 |
| Idemia | Sigma Lite | - |
| Idemia | Sigma Lite\+ Firmware | < 4.15.5 |
| Idemia | Sigma Lite\+ | - |
| Idemia | Sigma Extreme Firmware | < 4.15.5 |
| Idemia | Sigma Extreme | - |
| Idemia | Sigma Wide Firmware | < 4.15.5 |
| Idemia | Sigma Wide | - |
| Idemia | Morphowave Compact Firmware | < 2.12.2 |
| Idemia | Morphowave Compact | - |
| Idemia | Morphowave Xp Firmware | < 2.12.2 |
| Idemia | Morphowave Xp | - |
| Idemia | Visionpass Firmware | < 2.12.2 |
| Idemia | Visionpass | - |
| Idemia | Morphowave Sp Firmware | < 1.2.7 |
| Idemia | Morphowave Sp | - |
Related Weaknesses (CWE)
References
- https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2Vendor Advisory
- https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2Vendor Advisory
FAQ
What is CVE-2023-33221?
CVE-2023-33221 is a vulnerability with a CVSS score of 6.8 (MEDIUM). When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that co...
How severe is CVE-2023-33221?
CVE-2023-33221 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-33221?
Check the references section above for vendor advisories and patch information. Affected products include: Idemia Sigma Lite Firmware, Idemia Sigma Lite, Idemia Sigma Lite\+ Firmware, Idemia Sigma Lite\+, Idemia Sigma Extreme Firmware.