Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services.

This issue affects:

Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5.
Insignia TV with FireOS 7.6.3.3.

Project Subscriptions

Vendors Products
Fire Os Subscribe
Fire Tv Stick 3rd Gen Subscribe
Bestbuy Subscribe
Insignia Tv Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-23641 Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3.
Fixes

Solution

An automatic firmware update to the following versions fixes the issue: Amazon Fire TV Stick 3rd gen version 6.2.9.5 Insignia TV with FireOS version 7.6.3.3


Workaround

No workaround given by the vendor.

History

Thu, 30 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Bitdefender

Published:

Updated: 2025-01-30T15:00:50.049Z

Reserved: 2023-03-14T09:59:35.119Z

Link: CVE-2023-1385

cve-icon Vulnrichment

Updated: 2024-08-02T05:49:11.227Z

cve-icon NVD

Status : Modified

Published: 2023-05-03T13:15:10.290

Modified: 2024-11-21T07:39:04.880

Link: CVE-2023-1385

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses