9.8

CVE-2023-33221

Heap Buffer Overflow when reading DESFire card









When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying 
internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code 
Execution on the targeted device. This is especially problematic if you use Default DESFire key.







Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IdemiaSigma Lite Firmware Version < 4.15.5
   IdemiaSigma Lite Version-
IdemiaSigma Lite+ Firmware Version < 4.15.5
   IdemiaSigma Lite+ Version-
IdemiaSigma Extreme Firmware Version < 4.15.5
   IdemiaSigma Extreme Version-
IdemiaSigma Wide Firmware Version < 4.15.5
   IdemiaSigma Wide Version-
IdemiaMorphowave Compact Firmware Version < 2.12.2
   IdemiaMorphowave Compact Version-
IdemiaMorphowave Xp Firmware Version < 2.12.2
   IdemiaMorphowave Xp Version-
IdemiaVisionpass Firmware Version < 2.12.2
   IdemiaVisionpass Version-
IdemiaMorphowave Sp Firmware Version < 1.2.7
   IdemiaMorphowave Sp Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.03% 0.592
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
a87f365f-9d39-4848-9b3a-58c7cae69cab 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf
Vendor Advisory