CVE-2023-33248

Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relevant commands via an audio signal between 16 and 22 kHz (often outside the range of human adult hearing). Commands at these frequencies are essentially never spoken by authorized actors, but a substantial fraction of the commands are successful.
References
Link Resource
https://arxiv.org/abs/2305.10358 Third Party Advisory
https://cios2023.org/papers Third Party Advisory
https://github.com/reveondivad/nuance Exploit Third Party Advisory
https://sites.google.com/view/nuitattack/home Third Party Advisory
https://www.usenix.org/system/files/sec23fall-prepub-261-xia-qi.pdf Exploit Technical Description Third Party Advisory
https://youtu.be/3gEc5ZFWIWo Exploit Technical Description Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:amazon:alexa:8960323972:*:*:*:*:*:*:*
OR cpe:2.3:h:amazon:echo_dot:-:*:2nd_gen:*:*:*:*:*
cpe:2.3:h:amazon:echo_dot:-:*:3rd_gen:*:*:*:*:*

History

01 Jun 2023, 17:20

Type Values Removed Values Added
References (MISC) https://arxiv.org/abs/2305.10358 - (MISC) https://arxiv.org/abs/2305.10358 - Third Party Advisory
References (MISC) https://youtu.be/3gEc5ZFWIWo - (MISC) https://youtu.be/3gEc5ZFWIWo - Exploit, Technical Description, Third Party Advisory
References (MISC) https://www.usenix.org/system/files/sec23fall-prepub-261-xia-qi.pdf - (MISC) https://www.usenix.org/system/files/sec23fall-prepub-261-xia-qi.pdf - Exploit, Technical Description, Third Party Advisory
References (MISC) https://cios2023.org/papers - (MISC) https://cios2023.org/papers - Third Party Advisory
References (MISC) https://sites.google.com/view/nuitattack/home - (MISC) https://sites.google.com/view/nuitattack/home - Third Party Advisory
References (MISC) https://github.com/reveondivad/nuance - (MISC) https://github.com/reveondivad/nuance - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6
First Time Amazon alexa
Amazon echo Dot
Amazon
CPE cpe:2.3:h:amazon:echo_dot:-:*:3rd_gen:*:*:*:*:*
cpe:2.3:h:amazon:echo_dot:-:*:2nd_gen:*:*:*:*:*
cpe:2.3:o:amazon:alexa:8960323972:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

24 May 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-24 22:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-33248

Mitre link : CVE-2023-33248

CVE.ORG link : CVE-2023-33248


JSON object : View

Products Affected

amazon

  • echo_dot
  • alexa