Back

Improper JPAKE implementation allows offline PIN brute-forcing

Publication date: May 3rd, 2023


CVE ID:
CVE-2023-1385
CVSS scrore:
7.1 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Affected vendors:
Amazon
Affected products:
Fire TV Stick 3rd gen
Vulnerability details:

Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3.

Credit:
Bitdefender IoT Research Team