CVE-2023-50810: Code Injection
In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allow persistent arbitrary code execution with Linux kernel privileges. A failure to correctly handle the return value of the setenv command can be used to override the kernel command-line parameters and ultimately bypass the Secure Boot implementation. This affects PLAY5 gen 2, PLAYBASE, PLAY:1, One, One SL, and Amp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50810?
CVE-2023-50810 is classified as a critical vulnerability due to its potential for arbitrary code execution with Linux kernel privileges.
How do I fix CVE-2023-50810?
To mitigate CVE-2023-50810, update your Sonos products to version 11.12 for Sonos S1 or version 15.9 for Sonos S2.
What products are affected by CVE-2023-50810?
CVE-2023-50810 affects certain Sonos products running firmware versions prior to Sonos S1 Release 11.12 and S2 Release 15.9.
How does CVE-2023-50810 impact my Sonos devices?
CVE-2023-50810 allows for persistent arbitrary code execution, which could compromise the security and functionality of affected Sonos devices.
Is CVE-2023-50810 remote exploit capable?
Yes, CVE-2023-50810 can be exploited remotely due to its nature of allowing arbitrary code execution.