CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.8. It may be remotely exploitable.
CVE
CVE-2023-33221
Severity
MEDIUM
CVSS
6.8
EPSS
1.03%
Original NVD Description
When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is especially problematic if you use Default DESFire key.
Related CVEs
Other vulnerabilities affecting the same vendor(s)