Critical severity9.1NVD Advisory· Published Dec 15, 2023· Updated Jun 17, 2026
CVE-2023-33220
CVE-2023-33220
Description
During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some attributes to check. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device
Affected products
15cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:*range: <4.15.5
- cpe:2.3:o:idemia:sigma_lite\+_firmware:*:*:*:*:*:*:*:*range: <4.15.5
- (no CPE)range: 0
cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:*range: <4.15.5
- (no CPE)range: 0
cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:*range: <4.15.5
- (no CPE)range: 0
- cpe:2.3:o:idemia:morphowave_compact_firmware:*:*:*:*:*:*:*:*Range: <2.12.2
cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:*range: <1.2.7
- (no CPE)range: 0
- Range: 0
- Range: 0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.