Записи Sonos
19 опубликованных записей вендора sonos.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 15
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-416 Use After Free3
- CWE-121 Stack-based Buffer Overflow3
- CWE-191 Integer Underflow (Wrap or Wraparound)2
- CWE-122 Heap-based Buffer Overflow2
- CWE-787 Out-of-bounds Write2
- CWE-125 Out-of-bounds Read2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2022-24049Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systesonos · s1 · CWE-121 | Критическая9,8 | — | 7,2 % | 18 февр. 2022 г. |
39Наблюдать | CVE-2026-4149Эксплойта нет | Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerabilitysonos · era 300 firmware · CWE-119 | Критическая9,8 | — | 1,1 % | 10 апр. 2026 г. |
38Наблюдать | CVE-2018-11316Эксплойта нет | The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack.sonos · sonos firmware · CWE-20 | Критическая9,6 | — | 1,3 % | 3 июл. 2018 г. |
36Наблюдать | CVE-2022-24046Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1sonos · s1 · CWE-191 | Высокая8,8 | — | 4,1 % | 18 февр. 2022 г. |
35Наблюдать | CVE-2024-5269Эксплойта нет | Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerabilitysonos · era 100 firmware · CWE-416 | Высокая8,8 | — | 1,2 % | 6 июн. 2024 г. |
35Наблюдать | CVE-2023-27355Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220.sonos · one firmware · CWE-121 | Высокая8,8 | — | 0,8 % | 20 апр. 2023 г. |
35Наблюдать | CVE-2023-27352Эксплойта нет | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220.sonos · one firmware · CWE-416 | Высокая8,8 | — | 0,8 % | 20 апр. 2023 г. |
35Наблюдать | CVE-2024-5267Эксплойта нет | Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerabilitysonos · era 100 firmware · CWE-787 | Высокая8,8 | — | 0,7 % | 6 июн. 2024 г. |
35Наблюдать | CVE-2025-1048Эксплойта нет | Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerabilitysonos · s1 · CWE-416 | Высокая8,8 | — | 0,5 % | 23 апр. 2025 г. |
35Наблюдать | CVE-2025-1050Эксплойта нет | Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerabilitysonos · s2 · CWE-787 | Высокая8,8 | — | 0,4 % | 23 апр. 2025 г. |
35Наблюдать | CVE-2025-1049Эксплойта нет | Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerabilitysonos · s1 · CWE-122 | Высокая8,8 | — | 0,4 % | 23 апр. 2025 г. |
35Наблюдать | CVE-2025-1051Эксплойта нет | Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerabilitysonos · era 300 firmware · CWE-122 | Высокая8,8 | — | 0,4 % | 2 июн. 2025 г. |
31Наблюдать | CVE-2023-50809Эксплойта нет | In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an informatCWE-121 | Высокая7,8 | — | 0,4 % | 12 авг. 2024 г. |
27Наблюдать | CVE-2020-9285Эксплойта нет | Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attachesonos · one firmware · CWE-1191 | Средняя6,8 | — | 0,5 % | 20 окт. 2022 г. |
26Наблюдать | CVE-2023-27353Эксплойта нет | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-3sonos · one firmware · CWE-125 | Средняя6,5 | — | 0,6 % | 20 апр. 2023 г. |
26Наблюдать | CVE-2023-27354Эксплойта нет | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-3sonos · one firmware · CWE-190 | Средняя6,5 | — | 0,6 % | 20 апр. 2023 г. |
26Наблюдать | CVE-2024-5268Эксплойта нет | Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerabilitysonos · era 100 firmware · CWE-125 | Средняя6,5 | — | 0,5 % | 6 июн. 2024 г. |
24Наблюдать | CVE-2023-50810Эксплойта нет | In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware CWE-94 | Средняя6,0 | — | 0,8 % | 12 авг. 2024 г. |
17Наблюдать | CVE-2024-5256Эксплойта нет | Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerabilitysonos · era 100 firmware · CWE-191 | Средняя4,3 | — | 0,4 % | 6 июн. 2024 г. |
- CVE-2022-2404941В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 syste
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %sonos · s118 февр. 2022 г.
- CVE-2026-414939Наблюдать
Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sonos · era 300 firmware10 апр. 2026 г.
- CVE-2018-1131638Наблюдать
The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack.
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %sonos · sonos firmware3 июл. 2018 г.
- CVE-2022-2404636Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %sonos · s118 февр. 2022 г.
- CVE-2024-526935Наблюдать
Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sonos · era 100 firmware6 июн. 2024 г.
- CVE-2023-2735535Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sonos · one firmware20 апр. 2023 г.
- CVE-2023-2735235Наблюдать
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sonos · one firmware20 апр. 2023 г.
- CVE-2024-526735Наблюдать
Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sonos · era 100 firmware6 июн. 2024 г.
- CVE-2025-104835Наблюдать
Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sonos · s123 апр. 2025 г.
- CVE-2025-105035Наблюдать
Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sonos · s223 апр. 2025 г.
- CVE-2025-104935Наблюдать
Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sonos · s123 апр. 2025 г.
- CVE-2025-105135Наблюдать
Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sonos · era 300 firmware2 июн. 2025 г.
- CVE-2023-5080931Наблюдать
In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an informat
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %12 авг. 2024 г.
- CVE-2020-928527Наблюдать
Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attache
СредняяCVSS 6,8Эксплойта нетEPSS 0 %sonos · one firmware20 окт. 2022 г.
- CVE-2023-2735326Наблюдать
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-3
СредняяCVSS 6,5Эксплойта нетEPSS 1 %sonos · one firmware20 апр. 2023 г.
- CVE-2023-2735426Наблюдать
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-3
СредняяCVSS 6,5Эксплойта нетEPSS 1 %sonos · one firmware20 апр. 2023 г.
- CVE-2024-526826Наблюдать
Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 0 %sonos · era 100 firmware6 июн. 2024 г.
- CVE-2023-5081024Наблюдать
In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware
СредняяCVSS 6,0Эксплойта нетEPSS 1 %12 авг. 2024 г.
- CVE-2024-525617Наблюдать
Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability
СредняяCVSS 4,3Эксплойта нетEPSS 0 %sonos · era 100 firmware6 июн. 2024 г.