ZDI-23-448: (Pwn2Own) Sonos One Speaker msprox Endpoint Out-Of-Bounds Read Information Disclosure Vulnerability
Published Apr 14, 2023
·Updated
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Sonos One Speaker
Event History
Apr 14, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Mar 25, 2025
Advisory Published
via ZDI·01:03 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-448?
The severity of ZDI-23-448 is high due to its potential for sensitive information disclosure without authentication.
2
How do I fix ZDI-23-448?
To fix ZDI-23-448, ensure you update your Sonos One Speaker to the latest security release provided by Sonos.
3
Who can exploit ZDI-23-448?
ZDI-23-448 can be exploited by network-adjacent attackers without the need for authentication.
4
What type of information can be disclosed by exploiting ZDI-23-448?
Exploiting ZDI-23-448 can lead to the disclosure of sensitive information from affected Sonos One Speaker installations.
5
Is authentication required to exploit ZDI-23-448?
No, authentication is not required to exploit ZDI-23-448, making it more critical.