CVE-2023-6317 Details
Description
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN. Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA webOS 5.5.0 - 04.50.51 running on OLED55CXPUA webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 9, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/ | CVE | ExploitThird Party Advisory |
| https://lgsecurity.lge.com/bulletins/tv#updateDetails | CVE | Vendor Advisory |
| https://bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/ | [email protected] | ExploitThird Party Advisory |
| https://lgsecurity.lge.com/bulletins/tv#updateDetails | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lg webos | 4.9.7 5.5.0 6.3.3-442 7.3.1-43 |
CPE
Remediation
| |
| lg lg43um7000pla | All versions |
CPE
Remediation
| |
| lg oled55cxpua | All versions |
CPE
Remediation
| |
| lg oled48c1pub | All versions |
CPE
Remediation
| |
| lg oled55a23la | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Feb 7, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 18, 2024 | CVE Modified | [email protected] |
| Apr 9, 2024 | New CVE Received | [email protected] |