Описание
The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.
Ссылки
- Press/Media CoverageThird Party Advisory
- Press/Media CoverageThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:h:roku:roku_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:roku:roku:-:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00454
Низкий
9.6 Critical
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 9.6
github
больше 3 лет назад
The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.
EPSS
Процентиль: 63%
0.00454
Низкий
9.6 Critical
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-20