CVE-2023-1383
 
Severity Score
4.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible.
This issue affects:
Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5.
Insignia TV with FireOS versions prior to 7.6.3.3.
*Credits:
Bitdefender IoT Research Team
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-03-14 CVE Reserved
- 2023-05-03 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-841: Improper Enforcement of Behavioral Workflow
CAPEC
- CAPEC-153: Input Data Manipulation
References (1)
URL | Tag | Source |
---|---|---|
https://www.bitdefender.com/blog/labs/vulnerabilities-identified-amazon-fire-tv-stick-insignia-fire-os-tv-series | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Amazon Search vendor "Amazon" | Fire Os Search vendor "Amazon" for product "Fire Os" | < 6.2.9.5 Search vendor "Amazon" for product "Fire Os" and version " < 6.2.9.5" | - |
Affected
| in | Amazon Search vendor "Amazon" | Fire Tv Stick 3rd Gen Search vendor "Amazon" for product "Fire Tv Stick 3rd Gen" | - | - |
Safe
|
Amazon Search vendor "Amazon" | Fire Os Search vendor "Amazon" for product "Fire Os" | < 7.6.3.3 Search vendor "Amazon" for product "Fire Os" and version " < 7.6.3.3" | - |
Affected
| in | Bestbuy Search vendor "Bestbuy" | Insignia Tv Search vendor "Bestbuy" for product "Insignia Tv" | - | - |
Safe
|