PT-2022-21783 · Sony · Ps4+1

Andy Nguyen

·

Published

2022-09-28

·

Updated

2022-09-30

·

CVE-2022-3349

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sony PS4 and PS5 (affected versions not specified)
Description A critical issue affects the exFAT Handler component, specifically the UVFAT readupcasetable function. The manipulation of the dataLength argument leads to a heap-based buffer overflow. This issue can be exploited by launching an attack on the physical device.
Recommendations Upgrade the affected exFAT Handler component to a newer version. As a temporary workaround, consider restricting access to the UVFAT readupcasetable function until a patch is available. Avoid manipulating the dataLength argument in the affected component until the issue is resolved.

Exploit

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-3349

Affected Products

Ps4
Ps5