CVE-2022-24046
Published on: Not Yet Published
Last Modified on: 03/07/2022 02:34:00 PM UTC
Certain versions of One from Sonos contain the following vulnerability:
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to exploit this vulnerability. The specific flaw exists within the anacapd daemon. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15828.
- CVE-2022-24046 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Sonos - One Speaker version prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems)
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
ADJACENT_NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 8.3 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
ADJACENT_NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
ZDI-22-260 | Zero Day Initiative | www.zerodayinitiative.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Sonos | One | - | All | All | All |
Application | Sonos | S1 | All | All | All | All |
Application | Sonos | S2 | All | All | All | All |
- cpe:2.3:h:sonos:one:-:*:*:*:*:*:*:*:
- cpe:2.3:a:sonos:s1:*:*:*:*:*:*:*:*:
- cpe:2.3:a:sonos:s2:*:*:*:*:*:*:*:*:
Discovery Credit
Orange Tsai (@orange_8361) from DEVCORE Research Team
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-24046 : This vulnerability allows network-adjacent attackers to execute arbitrary code on affected install… twitter.com/i/web/status/1… | 2022-02-28 19:15:06 |