PT-2023-4543 · Tp Link · Tp-Link Tapo L630+4

Davide Bonaventura

+2

·

Published

2023-08-21

·

Updated

2024-05-07

·

CVE-2023-38909

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TP-Link Tapo L530 versions prior to 1.2.4 TP-Link Tapo L510E versions prior to 1.1.0 TP-Link Tapo L630 versions prior to 1.0.4 TP-Link Tapo P100 versions prior to 1.5.0 Tapo Application versions prior to 2.8.14
Description The issue is related to the lack of use of a random initialization vector with the cipher block chaining mode, allowing a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function. This can enable a brute force attack.
Recommendations For TP-Link Tapo L530 versions prior to 1.2.4, update to version 1.2.4 or later. For TP-Link Tapo L510E versions prior to 1.1.0, update to version 1.1.0 or later. For TP-Link Tapo L630 versions prior to 1.0.4, update to version 1.0.4 or later. For TP-Link Tapo P100 versions prior to 1.5.0, update to version 1.5.0 or later. For Tapo Application versions prior to 2.8.14, update to version 2.8.14 or later. As a temporary workaround, consider restricting access to the AES128-CBC function until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2023-04948
CVE-2023-38909

Affected Products

Tp-Link Tapo L510E
Tp-Link Tapo L530
Tp-Link Tapo L630
Tp-Link Tapo C100
Tapo Application