CVE-2023-6323

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
15/05/2024
Last modified:
11/02/2025

Description

ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wyze:cam_v3_firmware:4.36.11.5859:*:*:*:*:*:*:*
cpe:2.3:h:wyze:cam_v3:-:*:*:*:*:*:*:*
cpe:2.3:o:roku:indoor_camera_se_firmware:3.0.2.4679:*:*:*:*:*:*:*
cpe:2.3:h:roku:indoor_camera_se:-:*:*:*:*:*:*:*
cpe:2.3:o:owletcare:cam_firmware:*:*:*:*:*:*:*:* 4.2.11 (excluding)
cpe:2.3:h:owletcare:cam:-:*:*:*:*:*:*:*
cpe:2.3:o:owletcare:cam_2_firmware:*:*:*:*:*:*:*:* 4.2.10 (excluding)
cpe:2.3:h:owletcare:cam_2:-:*:*:*:*:*:*:*
cpe:2.3:a:throughtek:kalay_platform:-:*:*:*:*:*:*:*