Lucene search

K
cve[email protected]CVE-2023-38907
HistorySep 25, 2023 - 11:15 p.m.

CVE-2023-38907

2023-09-2523:15:09
web.nvd.nist.gov
54
cve-2023-38907
tplink
smart bulb
tapo
l530
security vulnerability
information disclosure

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.2%

An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still valid session key.

Affected configurations

NVD
Node
tp-linktapo_l530e_firmwareMatch1.0.0
AND
tp-linktapo_l530eMatch-
Node
tp-linktapoMatch2.8.14

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.2%

Related for CVE-2023-38907