MEDIUM · 4.3

CVE-2023-1384

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen ver...

Vulnerability Description

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AmazonFire Os< 6.2.9.5
AmazonFire Tv Stick 3Rd Gen-
BestbuyInsignia Tv-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-1384?

CVE-2023-1384 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen ver...

How severe is CVE-2023-1384?

CVE-2023-1384 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-1384?

Check the references section above for vendor advisories and patch information. Affected products include: Amazon Fire Os, Amazon Fire Tv Stick 3Rd Gen, Bestbuy Insignia Tv.