Back to Database
Status published
Critical
CVE-2023-33220
Stack Buffer Overflow when checking some attributes during retrofit
Vulnerability Description
During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some attributes to check. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-33220
Credits & Attribution
No credits recorded in the NVD database.
More from IDEMIA
View All →CVE-2023-4667
Stored Cross Site Scripting in webserver administration
High
8.1
CVE-2023-33222
Stack buffer overflow when reading DESFire card
Medium
6.8
CVE-2023-33221
Heap Buffer Overflow when reading DESFire card
Medium
6.8
CVE-2023-33219
Stack Buffer Overflow when checking retrofit package
Critical
9.1
CVE-2023-33218
Stack Buffer Overflow in a binary run at upgrade startup
Critical
9.1
Affected Vendor
IDEMIA
View all reports →Affected Software
SIGMA Lite & Lite +, SIGMA Wide, SIGMA Extreme, MorphoWave Compact/XP, VisionPass, MorphoWave SP
Vulnerable Versions:
0
Timeline
Official Publish:
December 15th, 2023
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N