First published: Wed May 03 2023(Updated: )
Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3.
Credit: cve-requests@bitdefender.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Fire OS | <6.2.9.5 | |
Amazon Fire TV Stick 3rd gen | ||
Amazon Fire OS | <7.6.3.3 | |
Bestbuy Insignia Tv |
An automatic firmware update to the following versions fixes the issue: Amazon Fire TV Stick 3rd gen version 6.2.9.5 Insignia TV with FireOS version 7.6.3.3
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1385 is a vulnerability that allows offline PIN brute-forcing due to the improper implementation of JPAKE, which can lead to unauthorized authentication to amzn.lightning services.
Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5 and Insignia TV with FireOS 7.6...
CVE-2023-1385 has a severity rating of 8.8 (high).
To fix CVE-2023-1385, update your Amazon Fire TV Stick 3rd gen to version 6.2.9.5 or later, and your Insignia TV with FireOS to version 7.6.3.3 or later.
For more information about CVE-2023-1385, you can refer to the following link: [Bitdefender Blog](https://www.bitdefender.com/blog/labs/vulnerabilities-identified-amazon-fire-tv-stick-insignia-fire-os-tv-series/).