Medium severity6.8NVD Advisory· Published Dec 15, 2023· Updated Jun 17, 2026
CVE-2023-33221
CVE-2023-33221
Description
When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is especially problematic if you use Default DESFire key.
Affected products
15- Range: 0
- Range: 0
cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:*range: <4.15.5
- cpe:2.3:o:idemia:sigma_lite\+_firmware:*:*:*:*:*:*:*:*range: <4.15.5
- (no CPE)range: 0
cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:*range: <4.15.5
- (no CPE)range: 0
cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:*range: <4.15.5
- (no CPE)range: 0
- cpe:2.3:o:idemia:morphowave_compact_firmware:*:*:*:*:*:*:*:*Range: <2.12.2
cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:*range: <1.2.7
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.