CVE-2023-1383

Description

An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

Remediation

Solution:

  • An automatic firmware update to the following versions fixes the issue: Amazon Fire TV Stick 3rd gen version 6.2.9.5 Insignia TV with FireOS version 7.6.3.3

Category

5.4
CVSS
Severity: Medium
CVSS 3.1 •
EPSS 0.06%
Third-Party Advisory bitdefender.com
Affected: AmazonFire TV Stick 3rd gen Fire TV Stick 3rd gen
Affected: Insignia TV with FireOS
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-1383?
CVE-2023-1383 has been scored as a medium severity vulnerability.
How to fix CVE-2023-1383?
To fix CVE-2023-1383: An automatic firmware update to the following versions fixes the issue: Amazon Fire TV Stick 3rd gen version 6.2.9.5 Insignia TV with FireOS version 7.6.3.3
Is CVE-2023-1383 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2023-1383 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-1383?
CVE-2023-1383 affects AmazonFire TV Stick 3rd gen Fire TV Stick 3rd gen, Insignia TV with FireOS .
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.