CVE-2023-1385: High severity amazon fire os vulnerability
Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services.
This issue affects:
Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-1385?
CVE-2023-1385 is a vulnerability that allows offline PIN brute-forcing due to the improper implementation of JPAKE, which can lead to unauthorized authentication to amzn.lightning services.
Which devices are affected by CVE-2023-1385?
Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5 and Insignia TV with FireOS 7.6...
What is the severity of CVE-2023-1385?
CVE-2023-1385 has a severity rating of 8.8 (high).
How can I fix CVE-2023-1385?
To fix CVE-2023-1385, update your Amazon Fire TV Stick 3rd gen to version 6.2.9.5 or later, and your Insignia TV with FireOS to version 7.6.3.3 or later.
Where can I find more information about CVE-2023-1385?
For more information about CVE-2023-1385, you can refer to the following link: [Bitdefender Blog](https://www.bitdefender.com/blog/labs/vulnerabilities-identified-amazon-fire-tv-stick-insignia-fire-os-tv-series/).