PT-2024-5067 · Wyze+3 · Wyze Cam V3+4

Alexandru Lazar

+1

·

Published

2024-05-15

·

Updated

2024-05-17

·

CVE-2023-6324

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ThroughTek Kalay SDK versions used in Owlet Cam v1, Owlet Cam v2, Wyze Cam v3, and Roku Indoor Camera SE
Description: The issue is related to the use of uninitialized variables in the Kalay SDK, which can be exploited by a remote attacker to disclose protected information. Additionally, the SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity.
Recommendations: For ThroughTek Kalay SDK versions used in Owlet Cam v1, Owlet Cam v2, Wyze Cam v3, and Roku Indoor Camera SE, consider disabling the use of DTLS sessions with unpredictable PSK identities until a patch is available. As a temporary workaround, restrict access to the affected devices to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

BDU:2024-05594
CVE-2023-6324

Affected Products

Owlet Cam V1
Owlet Cam V2
Roku Indoor Camera Se
Throughtek Kalay Sdk
Wyze Cam V3