ZDI-23-446: (Pwn2Own) Sonos One Speaker libsmb2 Integer Overflow Information Disclosure Vulnerability
Published Apr 14, 2023
·Updated
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Sonos One Speaker
Event History
Apr 14, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Mar 25, 2025
Advisory Published
via ZDI·01:03 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-446?
The severity of ZDI-23-446 is classified as high due to its potential for sensitive information disclosure.
2
How do I fix ZDI-23-446?
To fix ZDI-23-446, ensure that you apply the latest firmware update provided by Sonos for the One Speaker.
3
Who is affected by ZDI-23-446?
ZDI-23-446 affects all installations of the Sonos One Speaker that have not been updated to the latest version.
4
Can ZDI-23-446 be exploited remotely?
Yes, ZDI-23-446 can be exploited by network-adjacent attackers since no authentication is required.
5
What type of information can be disclosed due to ZDI-23-446?
ZDI-23-446 potentially allows the disclosure of sensitive user information from affected Sonos One Speakers.