CVE-2023-33217
Estado: ModificadaAlta (7.5)—
By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the terminal. the only way to recover the terminal is by sending back the terminal to the manufacturer
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.68%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (8)
CWE
- CWE-20
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-33217",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "a87f365f-9d39-4848-9b3a-58c7cae69cab",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "a87f365f-9d39-4848-9b3a-58c7cae69cab",
"affectedData": [
{
"vendor": "IDEMIA",
"product": "SIGMA Lite & Lite +",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.15.5",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "IDEMIA",
"product": "SIGMA Wide",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.15.5",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "IDEMIA",
"product": "SIGMA Extreme",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.15.5",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "IDEMIA",
"product": "MorphoWave Compact/XP",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.12.2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "IDEMIA",
"product": "VisionPass",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.12.2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "IDEMIA",
"product": "MorphoWave SP",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.2.7",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-12-15T11:15:08.960",
"references": [
{
"url": "https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf",
"tags": [
"Vendor Advisory"
],
"source": "a87f365f-9d39-4848-9b3a-58c7cae69cab"
},
{
"url": "https://www.idemia.com/wp-content/uploads/2023/11/Security-Advisory-SA-2023-05-2.pdf",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "a87f365f-9d39-4848-9b3a-58c7cae69cab",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "\nBy abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent \ndenial of service for the terminal. the only way to recover the terminal is by sending back the terminal to the manufacturer"
},
{
"lang": "es",
"value": "Al abusar de un defecto de diseño en el mecanismo de actualización del firmware del terminal afectado, es posible provocar una denegación permanente de servicio para el terminal. La única forma de recuperar el terminal es devolviéndolo al fabricante."
}
],
"lastModified": "2026-06-17T06:01:20.093",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:idemia:sigma_lite_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "983A7DAD-1995-4A8A-8714-D47D4E90ABF2",
"versionEndExcluding": "4.15.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:idemia:sigma_lite:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E2F8847F-E51A-4A64-A2D4-FCDD193E7AFA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:idemia:sigma_lite\\+_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2582E12-D19F-4660-A98C-6941C8C9081D",
"versionEndExcluding": "4.15.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:idemia:sigma_lite\\+:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2BB49653-25EA-4F69-A1B7-0ACA58F85FF1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:idemia:sigma_extreme_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "865DE0C9-5384-45BD-AF81-5C416FCB962A",
"versionEndExcluding": "4.15.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:idemia:sigma_extreme:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4FB05B6D-7D4C-4148-A05A-751B272B0E25"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:idemia:sigma_wide_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E2D74C2-6C83-4111-B410-E81C7414309B",
"versionEndExcluding": "4.15.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:idemia:sigma_wide:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BE86F813-6021-4FEB-86A9-B7013EEB4416"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:idemia:morphowave_compact_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8BDA2ED3-4875-45EB-8489-8C6B8F44EF2A",
"versionEndExcluding": "2.12.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:idemia:morphowave_compact:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B36E662E-C713-47E5-B07E-F0D9F1C63E9D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:idemia:morphowave_xp_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEAD097B-E5A8-492F-9ABB-75D5D15A8F9F",
"versionEndExcluding": "2.12.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:idemia:morphowave_xp:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2FA7252B-5871-4A13-B41D-752A5EA276F1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:idemia:visionpass_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1ED8DCF7-F85C-4513-BF69-5FE2D7185A96",
"versionEndExcluding": "2.12.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:idemia:visionpass:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CDABE653-294E-478C-B458-F9A1206A0E7E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:idemia:morphowave_sp_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF554F0F-8E5D-40A2-A676-8984AB685CEE",
"versionEndExcluding": "1.2.7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:idemia:morphowave_sp:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AFD369B0-119B-497B-9353-AB5E5E267FF9"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "a87f365f-9d39-4848-9b3a-58c7cae69cab"
}