CVE Vulnerabilities

CVE-2023-38909

Published: Aug 22, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.

Affected Software

NameVendorStart VersionEnd Version
TapoTp-link2.8.14 (including)2.8.14 (including)
Tapo_l530e_firmwareTp-link1.0.0 (including)1.0.0 (including)

References