Impersonation Attack via Unverified Messages
CVE-2023-6323

6.5MEDIUM

Key Information:

Vendor

Throughtek

Status
Vendor
CVE Published:
15 May 2024

What is CVE-2023-6323?

The ThroughTek Kalay SDK is susceptible to a vulnerability that fails to verify the authenticity of incoming messages. This lack of robust verification mechanisms allows an attacker to impersonate a legitimate authoritative server, potentially leading to unauthorized access or manipulation of data. Users of the Kalay SDK should be aware of this vulnerability's implications and take necessary precautions to mitigate risks associated with unauthorized impersonation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Kalay SDK 0 < 4.3.4.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexandru Lazar
Radu Basaraba
.