Skip to main content
  • 选购
  • 音响
  • 学习
  • 支持
  • 专业

Security Advisory: 2024-0001

Advisory ID: SSA-2024-0001
Severity: High
Issue Date: 2024-08-01
CVE(s): CVE-2023-50810, CVE-2023-50809

Synopsis: Recent software updates address multiple security vulnerabilities (CVE-2023-50810, CVE-2023-50809)

1. Impacted Products

  • All S1 and S2 Systems.

Affected versions: All releases prior to Sonos S2 release 15.9, and Sonos S1 release 11.12

2. Introduction
Multiple vulnerabilities were privately reported to Sonos. Updates are available to remediate these vulnerabilities in affected Sonos products.

3. Persistent Code Execution (CVE-2023-50810)
Description: A vulnerability exists in the U-Boot component of the firmware which would allow for persistent arbitrary code execution with Linux kernel privileges.
Known Attack Vectors: A malicious actor with physical access to the device or by obtaining write access to the flash memory through a separate runtime vulnerability may be able to exploit this.
Resolution: To remediate CVE-2023-50810 apply the update Sonos S2 release 15.9
Workarounds: None
Additional Documentation: None
Notes: None
Acknowledgments: Sonos would like to thank Alexander Plaskett and NCC Group for their responsible disclosure by reporting this issue to us.

4. Remote Code Execution (CVE-2023-50809)
Description: A vulnerability exists in the affected devices wireless driver that does not properly validate an information element while negotiating a WPA2 four-way handshake.
Known Attack Vectors: A low-privileged, close-proximity attacker could exploit this vulnerability to remotely execute arbitrary code.
Resolution: To remediate CVE-2023-50809 apply the update Sonos S2 release 15.9
Workarounds: None
Additional Documentation: The link to the MediaTek driver security advisory lives here: https://corp.mediatek.com/product-security-bulletin/March-2024 (https://corp.mediatek.com/product-security-bulletin/March-2024)
Notes: None
Acknowledgments: Sonos would like to thank Alexander Plaskett and NCC Group for their responsible disclosure by reporting this issue to us.

不错过任何一个节拍或优惠

订阅即可获取有关新产品的最新动态和专属优惠。

您同意接收来自Sonos的动态、促销优惠和其他消息。您可以随时退订。有关更多信息,请查阅我们的《 Privacy Statement》。

帮助

  • 客户
  • 联系我们
  • Sonos社区

帮助

优惠

  • 清仓
  • Sonos测试版

优惠

Sonos简介

  • 我们的公司
  • 新闻
  • 媒体工具包
  • 招贤纳士
  • 投资者
  • 可持续发展和影响力
  • 创始故事
  • Sonos App

Sonos简介

面向企业

  • 安装解决方案
  • 开发者门户
  • Works with Sonos

面向企业

类别

  • 耳机
  • 音响
  • 便携式音响
  • 家庭影院
  • 条形音响
  • 建筑
  • 音频组件
  • 配件

类别

产品

  • Sonos Ace
  • Arc
  • Beam(第2代)
  • Ray
  • Era 100
  • Era 300
  • Roam SL
  • Move 2
  • Sub(第3代)
  • Sub Mini
  • Five
  • Amp
  • Port

产品

© 2026 Sonos, Inc.
  • 法律信息
  • 隐私声明
  • 无障碍服务
  • 符合性
  • 网站地图
  • 安全性