Security Advisory

CVE-2018-11314

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-07-03 00:00:00
Last updated 2024-08-05 08:01:52
Assigner mitre
State PUBLISHED

Description

The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.