One Firmware
Sonos · 5 CVEs
CVE-2023-27355
HIGH
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One S…
Apr 20, 2023
CVE-2023-27354
MEDIUM
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Son…
Apr 20, 2023
CVE-2023-27353
MEDIUM
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Son…
Apr 20, 2023
CVE-2023-27352
HIGH
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One S…
Apr 20, 2023
CVE-2020-9285
MEDIUM
Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardwar…
Oct 20, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-27355 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not… | HIGH | 0.81% | Apr 20, 2023 |
| CVE-2023-27354 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authenticatio… | MEDIUM | 0.63% | Apr 20, 2023 |
| CVE-2023-27353 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authenticatio… | MEDIUM | 0.63% | Apr 20, 2023 |
| CVE-2023-27352 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not… | HIGH | 0.78% | Apr 20, 2023 |
| CVE-2020-9285 | Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI E… | MEDIUM | 0.48% | Oct 20, 2022 |
Showing 1 to 5 of 5 CVEs