NA

CVE-2023-1385

Published: 03/05/2023 Updated: 12/05/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions before 6.2.9.5. Insignia TV with FireOS 7.6.3.3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

amazon fire_os