← volver
CVE-2023-33221mediumCWE-122

Heap Buffer Overflow when reading DESFire card

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 6.8epss 1.0%
probabilidad de explotación
1.0%top 38% de las CVE
explotación observada
noninguna fuente lo reporta
When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is especially problematic if you use Default DESFire key.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H