PT-2022-9075 · Sonos · Sonos One

Nicolas Chatelain

·

Published

2022-10-20

·

Updated

2022-10-21

·

CVE-2020-9285

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sonos One versions 1st and 2nd generation
Description The issue allows partial or full memory access via attacker-controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard, which hosts the WiFi card on the device.
Recommendations For Sonos One versions 1st and 2nd generation, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2020-9285

Affected Products

Sonos One