VulnerabilityModified
CVE-2023-38909
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.
MEDIUM 6.5EPSS 0.80%
Does this matter?
Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.
Description
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.80% probability · 54th percentile
- CISA KEV
- Not listed
- Affected
- tp-link/tapo · tp-link/tapo l530e firmware
- Source
- cve@mitre.org
References
- https://arxiv.org/abs/2308.09019Third Party Advisory
- https://arxiv.org/pdf/2308.09019.pdfExploit, Technical Description, Third Party Advisory
- https://www.dmi.unict.it/giamp/smartbulbscanbehackedtohackintoyourhousehold/
- https://www.scitepress.org/Papers/2023/120929/120929.pdf
- https://www.scitepress.org/PublicationsDetail.aspx?ID=X/auBv7JrSo=&t=1Third Party Advisory
- https://arxiv.org/abs/2308.09019Third Party Advisory
- https://arxiv.org/pdf/2308.09019.pdfExploit, Technical Description, Third Party Advisory
- https://www.dmi.unict.it/giamp/smartbulbscanbehackedtohackintoyourhousehold/
- https://www.scitepress.org/Papers/2023/120929/120929.pdf
- https://www.scitepress.org/PublicationsDetail.aspx?ID=X/auBv7JrSo=&t=1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.