First published: Fri Aug 25 2023(Updated: )
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability.
Affected Software | Affected Version | How to fix |
---|---|---|
LG LED Assistant |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is ZDI-23-1223.
The severity of ZDI-23-1223 is high with a CVSS score of 7.5.
The affected software is LG LED Assistant.
The vulnerability in LG LED Assistant allows remote attackers to disclose sensitive information through the /api/thumbnail endpoint.
No, authentication is not required to exploit the vulnerability in LG LED Assistant.
To fix the ZDI-23-1223 vulnerability in LG LED Assistant, it is recommended to apply the latest updates provided by LG, as mentioned in their security bulletin.