CVE-2022-24046: (Pwn2Own) Sonos One Speaker Integer Underflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to exploit this vulnerability. The specific flaw exists within the anacapd daemon. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15828.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker. Authentication is not required to exploit this vulnerability. The specific flaw exists within the anacapd daemon. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24046?
CVE-2022-24046 has been classified as a critical vulnerability due to its ability to allow arbitrary code execution without authentication.
How do I fix CVE-2022-24046?
To fix CVE-2022-24046, update your Sonos One Speaker or Sonos S2 to the versions 11.2.13 or 3.4.1 respectively or later.
What products are affected by CVE-2022-24046?
CVE-2022-24046 affects Sonos One Speaker prior to version 11.2.13 and Sonos S2 systems prior to version 3.4.1.
What type of attack is possible with CVE-2022-24046?
CVE-2022-24046 allows network-adjacent attackers to execute arbitrary code on the affected devices.
Is authentication required to exploit CVE-2022-24046?
No, authentication is not required to exploit CVE-2022-24046.