Notes on ThroughTek Kalay Vulnerabilities and Their Impact on the IoT Ecosystem
ID: fb73f780-d1f6-5c30-a8d5-1005e3e07478
STIX ID: report--fb73f780-d1f6-5c30-a8d5-1005e3e07478
Feed Name: Bitdefender Labs
Threat Score
Bitdefender IoT researchers disclosed four high-severity vulnerabilities in the ThroughTek Kalay platform (CVE-2023-6321–6324) that, when chained, allow local attackers to obtain AuthKey/DTLS PSK material, escalate to root, and execute commands on affected IoT cameras. The findings impact multiple vendors (Owlet, Wyze, Roku and others using the Kalay SDK), a coordinated disclosure and firmware/SDK patches were arranged and released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
