When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying
internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code
Execution on the targeted device. This is especially problematic if you use Default DESFire key.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Idemia
Subscribe
|
Morphowave Compact
Subscribe
Morphowave Compact Firmware
Subscribe
Morphowave Sp
Subscribe
Morphowave Sp Firmware
Subscribe
Morphowave Xp
Subscribe
Morphowave Xp Firmware
Subscribe
Sigma Extreme
Subscribe
Sigma Extreme Firmware
Subscribe
Sigma Lite
Subscribe
Sigma Lite\+
Subscribe
Sigma Lite\+ Firmware
Subscribe
Sigma Lite Firmware
Subscribe
Sigma Wide
Subscribe
Sigma Wide Firmware
Subscribe
Visionpass
Subscribe
Visionpass Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37391 | When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is especially problematic if you use Default DESFire key. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: IDEMIA
Published:
Updated: 2024-08-02T15:39:35.729Z
Reserved: 2023-05-18T14:32:49.223Z
Link: CVE-2023-33221
No data.
Status : Modified
Published: 2023-12-15T12:15:43.927
Modified: 2024-11-21T08:05:10.097
Link: CVE-2023-33221
No data.
OpenCVE Enrichment
No data.
EUVD