Skip to main content
  • Ofertă
  • Cumpără
  • Află
  • Asistență
  • Profesioniști
  • Coș

Security Advisory: 2024-0001

Advisory ID: SSA-2024-0001
Severity: High
Issue Date: 2024-08-01
CVE(s): CVE-2023-50810, CVE-2023-50809

Synopsis: Recent software updates address multiple security vulnerabilities (CVE-2023-50810, CVE-2023-50809)

1. Impacted Products

  • All S1 and S2 Systems.

Affected versions: All releases prior to Sonos S2 release 15.9, and Sonos S1 release 11.12

2. Introduction
Multiple vulnerabilities were privately reported to Sonos. Updates are available to remediate these vulnerabilities in affected Sonos products.

3. Persistent Code Execution (CVE-2023-50810)
Description: A vulnerability exists in the U-Boot component of the firmware which would allow for persistent arbitrary code execution with Linux kernel privileges.
Known Attack Vectors: A malicious actor with physical access to the device or by obtaining write access to the flash memory through a separate runtime vulnerability may be able to exploit this.
Resolution: To remediate CVE-2023-50810 apply the update Sonos S2 release 15.9
Workarounds: None
Additional Documentation: None
Notes: None
Acknowledgments: Sonos would like to thank Alexander Plaskett and NCC Group for their responsible disclosure by reporting this issue to us.

4. Remote Code Execution (CVE-2023-50809)
Description: A vulnerability exists in the affected devices wireless driver that does not properly validate an information element while negotiating a WPA2 four-way handshake.
Known Attack Vectors: A low-privileged, close-proximity attacker could exploit this vulnerability to remotely execute arbitrary code.
Resolution: To remediate CVE-2023-50809 apply the update Sonos S2 release 15.9
Workarounds: None
Additional Documentation: The link to the MediaTek driver security advisory lives here: https://corp.mediatek.com/product-security-bulletin/March-2024 (https://corp.mediatek.com/product-security-bulletin/March-2024)
Notes: None
Acknowledgments: Sonos would like to thank Alexander Plaskett and NCC Group for their responsible disclosure by reporting this issue to us.

Nu rata niciun ritm și nicio ofertă

Abonează-te pentru a primi ultimele noutăți despre produse noi și oferte exclusive.

Ești de acord să primești actualizări, oferte promoționale și alte mesaje de la Sonos. Te poți dezabona în orice moment. Pentru mai multe informații, consultă Declarația noastră de confidențialitate.

Ajutor

  • Cont
  • Status comandă
  • Expediere și livrare
  • Retururi
  • Hartă magazine
  • Contactează-ne
  • Condiții de vânzare
  • Comunitatea Sonos

Ajutor

Oferte

  • Ultima șansă
  • Certified Refurbished
  • Programul Sonos Upgrade
  • Sonos Beta

Oferte

Despre Sonos

  • Compania noastră
  • Știri
  • Kit-uri media
  • Cariere
  • Investitori
  • Sustenabilitate și impact
  • Cum a început
  • Blog
  • Aplicația Sonos
  • Recenzii

Despre Sonos

Pentru firme

  • Soluții instalate
  • Portal dezvoltatori
  • Profesii Sonos
  • Funcționează cu Sonos

Pentru firme

Categorii

  • Căști
  • Boxe
  • Boxe portabile
  • Home Theater
  • Soundbar-uri
  • Seturi
  • Arhitectural
  • Componente
  • Accesorii

Categorii

Produse

  • Sonos Play
  • Sonos Ace
  • Arc Ultra
  • Beam (Gen 2)
  • Ray
  • Era 100
  • Era 100 SL
  • Era 300
  • Roam 2
  • Move 2
  • Sub 4
  • Sub Mini
  • Five
  • Amp
  • Port

Produse

© 2026 Sonos, Inc.
  • Juridic
  • Declarație de confidențialitate
  • Accesibilitate
  • Conformitate
  • Hartă site
  • Securitate