Back

Improper Enforcement of Behavioral Workflow vulnerability in Amazon Fire TV Stick 3rd gen

Publication date: May 3rd, 2023


CVE ID:
CVE-2023-1383
CVSS scrore:
5.4 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected vendors:
Amazon
Affected products:
Fire TV Stick 3rd gen
Vulnerability details:

An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

Credit:
Bitdefender IoT Research Team