Vulnerability Description
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still valid session key.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tapo L530E Firmware | 1.0.0 |
| Tp-Link | Tapo L530E | - |
| Tp-Link | Tapo | 2.8.14 |
References
- https://arxiv.org/abs/2308.09019Technical DescriptionThird Party Advisory
- https://www.dmi.unict.it/giamp/smartbulbscanbehackedtohackintoyourhousehold/
- https://www.scitepress.org/Papers/2023/120929/120929.pdf
- https://www.scitepress.org/PublicationsDetail.aspx?ID=X/auBv7JrSo=&t=1Third Party Advisory
- https://arxiv.org/abs/2308.09019Technical DescriptionThird Party Advisory
- https://www.dmi.unict.it/giamp/smartbulbscanbehackedtohackintoyourhousehold/
- https://www.scitepress.org/Papers/2023/120929/120929.pdf
- https://www.scitepress.org/PublicationsDetail.aspx?ID=X/auBv7JrSo=&t=1Third Party Advisory
FAQ
What is CVE-2023-38907?
CVE-2023-38907 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encry...
How severe is CVE-2023-38907?
CVE-2023-38907 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-38907?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tapo L530E Firmware, Tp-Link Tapo L530E, Tp-Link Tapo.