PT-2024-5068 · Roku · Roku Indoor Camera Se
Alexandru Lazar
+1
·
Published
2024-05-15
·
Updated
2024-05-15
·
CVE-2023-6323
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Kalay SDK versions (affected versions not specified)
Owlet Cam version (affected versions not specified)
Owlet Cam v1
Owlet Cam v2
Wyze Cam v3
Roku Indoor Camera SE
Description:
The issue is related to insufficient authentication of received data, allowing an attacker to impersonate an authoritative server and potentially gain unauthorized access to protected information. This can be exploited by a remote attacker.
Recommendations:
For Kalay SDK, consider implementing proper message authentication mechanisms to verify the authenticity of received messages until a patch is available.
For Owlet Cam v1, Owlet Cam v2, Wyze Cam v3, and Roku Indoor Camera SE, restrict access to sensitive information and consider disabling remote access features until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Roku Indoor Camera Se