• Home
  • News
    • Alerts
    • Vulnerability
    • Malware/Spyware
    • Our Black List
    • News Treads
    • News of the front
  • Live
  • Exploits
  • Kali
  • Suricata
  • Wallpaper
  • Geeks
  • About us
  • Wanted
-=NWPC Switzerland=- [Hackers Group]

WHAT ARE YOU LOOKING FOR?

-=NWPC Switzerland=- [Hackers Group]
  • Home
  • News
    • Alerts
    • Vulnerability
    • Malware/Spyware
    • Our Black List
    • News Treads
    • News of the front
  • Live
  • Exploits
  • Kali
  • Suricata
  • Wallpaper
  • Geeks
  • About us
  • Wanted

Hackers Win $105,000 for Reporting Critical Security Flaws in Sonos One Speakers

Roger Wilco Alertes 30 mai 2023 Affichages : 431
Hackers Win $105,000 for Reporting Critical Security Flaws in Sonos One Speakers
Critical Security Flaws

Multiple security flaws uncovered in Sonos One wireless speakers could be potentially exploited to achieve information disclosure and remote code execution, the Zero Day Initiative (ZDI) said[1] in a report published last week.

The vulnerabilities were demonstrated by three different teams from Qrious Secure, STAR Labs, and DEVCORE at the Pwn2Own hacking contest held in Toronto late last year, netting them $105,000 in monetary rewards.

The list of four flaws, which impact Sonos One Speaker 70.3-35220, is below -

  • CVE-2023-27352[2] and CVE-2023-27355[3] (CVSS scores: 8.8) - Unauthenticated flaws that allow network-adjacent attackers to execute arbitrary code on affected installations.
  • CVE-2023-27353[4] and CVE-2023-27354[5] (CVSS score: 6.5) - Unauthenticated flaws that allow network-adjacent attackers to disclose sensitive information on affected installations.

While CVE-2023-27352 stems from when processing SMB directory query commands, CVE-2023-27355 exists within the MPEG-TS parser.

UPCOMING WEBINAR

Zero Trust + Deception: Learn How to Outsmart Attackers!

Successful exploitation of both shortcomings could permit an attacker to execute arbitrary code in the context of the root user.

Both the information disclosure flaws can be combined separately with other flaws in the systems to achieve code execution with elevated privileges.

Following responsible disclosure on December 29, 2022, the flaws were addressed by Sonos as part of Sonos S2 and S1 software versions 15.1 and 11.7.1, respectively. Users are recommended to apply the latest patches to mitigate potential risks.

Found this article interesting? Follow us on Twitter [6] and LinkedIn[7] to read more exclusive content we post.

References

  1. ^said (www.thezdi.com)
  2. ^CVE-2023-27352 (nvd.nist.gov)
  3. ^CVE-2023-27355 (nvd.nist.gov)
  4. ^CVE-2023-27353 (nvd.nist.gov)
  5. ^CVE-2023-27354 (nvd.nist.gov)
  6. ^Twitter (twitter.com)
  7. ^LinkedIn (www.linkedin.com)

Read more https://packetstormsecurity.com/news/view/34672/Hacker-Wins-105k-For-Reporting-Flaws-In-Sonos-One-Speakers.html

Article précédent : Organizations Warned of Backdoor Feature in Hundreds of Gigabyte Motherboards Précédent Article suivant : Ubuntu Security Notice USN-6005-2 ≈ Packet Storm Suivant
Image

GENÈVE

Follow us on

  • fa fa-tumblr-square
  • fa fa-facebook-square

Most popular

Reflections on Ten Years Past The Snowden Revelations

25 mai 2023By Roger Wilco

Thousands Of Hacked Disney+ Accounts Are Already For Sale

16 novembre 2019By Roger Wilco

Microsoft Taps Eric Holder To Audit AnyVision Face Recognition

16 novembre 2019By Roger Wilco

Raritan CommandCenter Secure Gateway XML Injection

15 novembre 2019By Roger Wilco

Red Hat Security Advisory 2019-3840-01

12 novembre 2019By Roger Wilco

Red Hat Security Advisory 2019-3890-01

15 novembre 2019By Roger Wilco
Image
Back To Top

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"

Category

  • Exploits
  • Kali
  • Wallpaper
  • Suricata
  • Geeks
  • Wanted

Popular Sections

  • Alerts
  • Vulnerability
  • Live Attacks
  • Spywares/Malwares

About

  • About us
  • Advertising
  • Term of Use
  • Privacy Policy
© 2026 NWPC-CH.ORG by Roger Wilco
  • Home
  • News
    • Alerts
    • Vulnerability
    • Malware/Spyware
    • Our Black List
    • News Treads
    • News of the front
  • Exploits
  • Live
  • kali
  • Suricata
  • Wallpaper
  • Geeks
  • About us
  • Wanted
  • Login