CVE-2023-1383: Amazon Fire OS
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.
Affected products
- Amazon Fire OS: before 6.2.9.5 (fixed in 6.2.9.5); before 7.6.3.3 (fixed in 7.6.3.3)
Published 2023-05-03. Last modified 2026-06-17.