Improper JPAKE Implementation in Amazon Fire TV Stick and Insignia TV Allows Unauthorized Access
CVE-2023-1385
What is CVE-2023-1385?
The vulnerability arises from an improper implementation of JPAKE (Password Authenticated Key Exchange) in the affected devices, specifically allowing for offline brute-forcing of user PINs. Due to the initialization of random values to a known state, attackers can exploit this flaw to achieve unauthorized authentication, potentially compromising user accounts associated with Amazon services and allowing them access to sensitive features of the Fire TV Stick and Insignia TVs. This highlights the importance of robust security practices in implementing cryptographic protocols.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fire TV Stick 3rd gen 6.2.9.4
TV with FireOS 7.6.3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
