Beveiligingsadvies

CVE-2023-1385

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-05-03 12:33:31
Laatst bijgewerkt 2025-01-30 15:00:50
Toegewezen door Bitdefender
CVSS-score 7.1
Status PUBLISHED

Beschrijving

Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3.