Beveiligingsadvies

CVE-2023-33221

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-12-15 11:32:48
Laatst bijgewerkt 2024-08-02 15:39:35
Toegewezen door IDEMIA
CVSS-score 6.8
Status PUBLISHED

Beschrijving

When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is especially problematic if you use Default DESFire key.