PT-2024-5068 · Roku · Roku Indoor Camera Se

Alexandru Lazar

+1

·

Published

2024-05-15

·

Updated

2024-05-15

·

CVE-2023-6323

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Kalay SDK versions (affected versions not specified) Owlet Cam version (affected versions not specified) Owlet Cam v1 Owlet Cam v2 Wyze Cam v3 Roku Indoor Camera SE
Description: The issue is related to insufficient authentication of received data, allowing an attacker to impersonate an authoritative server and potentially gain unauthorized access to protected information. This can be exploited by a remote attacker.
Recommendations: For Kalay SDK, consider implementing proper message authentication mechanisms to verify the authenticity of received messages until a patch is available. For Owlet Cam v1, Owlet Cam v2, Wyze Cam v3, and Roku Indoor Camera SE, restrict access to sensitive information and consider disabling remote access features until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

BDU:2024-05595
CVE-2023-6323

Affected Products

Roku Indoor Camera Se