Article Details
Scrape Timestamp (UTC): 2024-04-09 13:12:53.224
Source: https://thehackernews.com/2024/04/researchers-discover-lg-smart-tv.html
Original Article Text
Click to Toggle View
Researchers Discover LG Smart TV Vulnerabilities Allowing Root Access. Multiple security vulnerabilities have been disclosed in LG webOS running on its smart televisions that could be exploited to bypass authorization and gain root access on the devices. The findings come from Romanian cybersecurity firm Bitdefender, which discovered and reported the flaws in November 2023. The issues were fixed by LG as part of updates released on March 22, 2024. The vulnerabilities are tracked from CVE-2023-6317 through CVE-2023-6320 and impact the following versions of webOS - A brief description of the shortcomings is as follows - Successful exploitation of the flaws could allow a threat actor to gain elevated permissions to the device, which, in turn, can be chained with CVE-2023-6318 and CVE-2023-6319 to obtain root access, or with CVE-2023-6320 to run arbitrary commands as the dbus user. "Although the vulnerable service is intended for LAN access only, Shodan, the search engine for Internet-connected devices, identified over 91,000 devices that expose this service to the Internet," Bitdefender said. A majority of the devices are located in South Korea, Hong Kong, the U.S., Sweden, Finland, and Latvia. Goodbye, Atlassian Server. Goodbye… Backups? Protect your data on Atlassian Cloud from disaster with Rewind's daily backups and on-demand restores. How to Update and Automate Outdated Security Processes Download the eBook for step-by-step guidance on how to update your security processes as your business grows.
Daily Brief Summary
Security researchers from Bitdefender identified multiple vulnerabilities in LG smart TVs running webOS.
The weaknesses could be exploited to bypass security measures and obtain root access to the televisions.
LG has addressed these issues through software updates released on March 22, 2024.
The vulnerabilities, with CVE IDs ranging from CVE-2023-6317 to CVE-2023-6320, affect certain versions of webOS.
An attacker could chain specific CVEs to elevate device permissions and execute commands as the dbus user.
Over 91,000 internet-connected LG smart TVs with exposed vulnerable services were identified worldwide, primarily in South Korea, Hong Kong, the U.S., Sweden, Finland, and Latvia.
The flaws were initially reported to LG in November 2023, leading to the recent fixes to mitigate potential risks.