CVE-2023-33111

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 1, 2024
Updated: Jan 13, 2025
CWE ID 129

Summary

CVE-2023-33111 is a newly discovered information disclosure vulnerability. It affects devices using the Analog Front End (AFE) calibration command. The issue arises when the Variable Gain Amplifier (VGA) calibration state set by the Analog-Digital Signal Processor (ADSP) exceeds the MAX_FBSP_STATE limit. As a result, the response payload contains sensitive information that should have remained confidential. This vulnerability could potentially be exploited by unauthorized users to gain unintended access to system details, posing a risk to data privacy and security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share