CVE-2023-33222: Idemia Morphowave Compact Firmware
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
When handling contactless cards, usage of a specific function to get additional information from the card which doesn't check the boundary on the data received while reading. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device
Affected products
- Idemia Morphowave Compact Firmware: before 2.12.2 (fixed in 2.12.2)
- Idemia Morphowave SP Firmware: before 1.2.7 (fixed in 1.2.7)
- Idemia Morphowave XP Firmware: before 2.12.2 (fixed in 2.12.2)
- Idemia Sigma Extreme Firmware: before 4.15.5 (fixed in 4.15.5)
- Idemia Sigma Lite+ Firmware: before 4.15.5 (fixed in 4.15.5)
- Idemia Sigma Lite Firmware: before 4.15.5 (fixed in 4.15.5)
- Idemia Sigma Wide Firmware: before 4.15.5 (fixed in 4.15.5)
- Idemia Visionpass Firmware: before 2.12.2 (fixed in 2.12.2)
Published 2023-12-15. Last modified 2026-06-17.