9.8

CVE-2023-33221

Heap Buffer Overflow when reading DESFire card









When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying 
internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code 
Execution on the targeted device. This is especially problematic if you use Default DESFire key.







Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Idemia ≫ Sigma Lite Firmware Version < 4.15.5
   Idemia ≫ Sigma Lite Version -
Idemia ≫ Sigma Lite+ Firmware Version < 4.15.5
   Idemia ≫ Sigma Lite+ Version -
Idemia ≫ Sigma Extreme Firmware Version < 4.15.5
   Idemia ≫ Sigma Extreme Version -
Idemia ≫ Sigma Wide Firmware Version < 4.15.5
   Idemia ≫ Sigma Wide Version -
Idemia ≫ Morphowave Compact Firmware Version < 2.12.2
   Idemia ≫ Morphowave Compact Version -
Idemia ≫ Morphowave Xp Firmware Version < 2.12.2
   Idemia ≫ Morphowave Xp Version -
Idemia ≫ Visionpass Firmware Version < 2.12.2
   Idemia ≫ Visionpass Version -
Idemia ≫ Morphowave Sp Firmware Version < 1.2.7
   Idemia ≫ Morphowave Sp Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.03% 0.592
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
a87f365f-9d39-4848-9b3a-58c7cae69cab 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf
Vendor Advisory