CVE-2023-1385: Amazon Fire OS
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3.
Affected products
- Amazon Fire OS: before 6.2.9.5 (fixed in 6.2.9.5); before 7.6.3.3 (fixed in 7.6.3.3)
Published 2023-05-03. Last modified 2026-06-17.