CVE-2023-1383: Medium severity amazon fire os vulnerability
An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible.
This issue affects:
Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-1383.
What is the severity of CVE-2023-1383?
The severity of CVE-2023-1383 is medium.
What is the affected software for CVE-2023-1383?
The affected software for CVE-2023-1383 includes Amazon Fire OS versions up to 6.2.9.5 and 7.6.3.3, and Bestbuy Insignia TV.
How does CVE-2023-1383 impact Amazon Fire TV Stick 3rd gen?
CVE-2023-1383 does not impact Amazon Fire TV Stick 3rd gen.
How do I fix CVE-2023-1383?
To fix CVE-2023-1383, update your software to version 6.2.9.5 or higher for Amazon Fire OS, and follow any patches or updates provided by Bestbuy for the Insignia TV.