Sonos Era 100 vulnerabilities
4 known vulnerabilities affecting sonos/era_100.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-5269P2HIGHCVSS 8.8v15.9 (build 75146030)2024-06-06
CVE-2024-5269 [HIGH] CWE-416 CVE-2024-5269: Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnera
Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of SMB2 messages. The
nvd
CVE-2024-5267P3HIGHCVSS 8.8v15.9 (build 75146030)2024-06-06
CVE-2024-5267 [HIGH] CWE-787 CVE-2024-5267: Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerability. This vu
Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of SMB2 messages
nvd
CVE-2024-5268P3MEDIUMCVSS 6.5v15.9 (build 75146030)2024-06-06
CVE-2024-5268 [MEDIUM] CWE-125 CVE-2024-5268: Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vu
Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of SMB
nvd
CVE-2024-5256P4MEDIUMCVSS 4.3v15.9 (build 75146030)2024-06-06
CVE-2024-5256 [MEDIUM] CWE-191 CVE-2024-5256: Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vul
Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of SMB2
nvd