VYPR

Security Advisory SA-2023-05-2

by Idemia

CVEs (2)

  • CVE-2023-33222MedDec 15, 2023
    risk 0.44cvss 6.8epss 0.01

    When handling contactless cards, usage of a specific function to get additional information from the card which doesn't check the boundary on the data received while reading. This allows a stack-based buffer overflow that could lead to a potential Remote Code…

  • CVE-2023-33221MedDec 15, 2023
    risk 0.44cvss 6.8epss 0.01

    When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is…