CVE-2023-6324
Published May 15, 2024ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity
Vendor/product archive
3 CVEs tagged to owletcare / cam_firmware — 0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.
ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity
ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.
A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make au…