CVE-2023-33217
By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the terminal. the only way to recover the terminal is by sending back the terminal to the manufacturer
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the terminal. the only way to recover the terminal is by sending back the terminal to the manufacturer
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- idemia/sigma lite firmware · idemia/sigma lite\+ firmware · idemia/sigma extreme firmware · idemia/sigma wide firmware · idemia/morphowave compact firmware · idemia/morphowave xp firmware · idemia/visionpass firmware · idemia/morphowave sp firmware
- Source
- a87f365f-9d39-4848-9b3a-58c7cae69cab
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.