CVE-2022-3349 MEDIUM

CVE-2022-3349: Sony PS4/PS5 exFAT UVFAT_readupcasetable heap-based overflow

Vendor Sony
Product PS4
Weakness CWE-119
Published September 28, 2022
Last update April 15, 2025

CVSS base score

6.8/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical device. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-209679.

Key dates

02Disclosure timeline

September 28, 2022 CVE published
April 15, 2025 Record updated