PT-2022-9075 · Sonos · Sonos One

·

CVE-2020-9285

·

Published

2022-10-20

·

Updated

2022-10-21

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sonos One versions 1st and 2nd generation
Description The issue allows partial or full memory access via attacker-controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard, which hosts the WiFi card on the device.
Recommendations For Sonos One versions 1st and 2nd generation, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9285

Affected Products

Sonos One