Arbitrary Code Execution Vulnerability in Sonos One Speaker by Sonos
CVE-2022-24046
9.8CRITICAL
What is CVE-2022-24046?
A vulnerability has been identified in the Sonos One Speaker that allows network-adjacent attackers to execute arbitrary code. The issue arises from the anacapd daemon's inability to properly validate user-supplied data, leading to an integer underflow that can cause unintended memory access. This flaw permits attackers to execute code with root privileges on affected devices without requiring authentication, making it a significant security concern for users of these devices.
Affected Version(s)
One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems)
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Orange Tsai (@orange_8361) from DEVCORE Research Team