First published: Wed May 03 2023(Updated: )
An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.
Credit: cve-requests@bitdefender.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Fire OS | <6.2.9.5 | |
Amazon Fire TV Stick 3rd gen | ||
Amazon Fire OS | <7.6.3.3 | |
Bestbuy Insignia Tv |
An automatic firmware update to the following versions fixes the issue: Amazon Fire TV Stick 3rd gen version 6.2.9.5 Insignia TV with FireOS version 7.6.3.3
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-1383.
The severity of CVE-2023-1383 is medium.
The affected software for CVE-2023-1383 includes Amazon Fire OS versions up to 6.2.9.5 and 7.6.3.3, and Bestbuy Insignia TV.
CVE-2023-1383 does not impact Amazon Fire TV Stick 3rd gen.
To fix CVE-2023-1383, update your software to version 6.2.9.5 or higher for Amazon Fire OS, and follow any patches or updates provided by Bestbuy for the Insignia TV.