8.8

CVE-2023-6324

Exploit

ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WyzeCam V3 Firmware Version4.36.11.5859
   WyzeCam V3 Version-
RokuIndoor Camera Se Firmware Version3.0.2.4679
   RokuIndoor Camera Se Version-
OwletcareCam Firmware Version < 4.2.11
   OwletcareCam Version-
OwletcareCam 2 Firmware Version < 4.2.10
   OwletcareCam 2 Version-
ThroughtekKalay Platform Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.59% 0.681
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cve-requests@bitdefender.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-457 Use of Uninitialized Variable

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.