Remote Code Execution Vulnerability in Sonos One Speaker by Sonos
CVE-2023-27352

8.8HIGH

Key Information:

Vendor

Sonos

Vendor
CVE Published:
20 April 2023

What is CVE-2023-27352?

The vulnerability in the Sonos One Speaker permits network-adjacent attackers to execute arbitrary code without authentication. This flaw lies in the processing of the SMB directory query command, where the absence of validation for object existence allows attackers to manipulate operations on unverified objects. Exploiting this weakness can enable an attacker to run malicious code with root privileges, posing significant risks to the device’s security and data integrity. For more technical details, refer to the advisory documentation.

Affected Version(s)

One Speaker 70.3-35220

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Toan (suto) Pham and Tri Dang from Qrious Secure
.