ThroughTek Update
2806Warning Date
Severity Level
Warning Number
Target Sector
17 June, 2021
● Critical
2021-3061
Communication and information technology
Description:
ThroughTek has released a security update to address two vulnerabilities in the following versions of :
- P2P Software Development Kit (SDK) :
- Versions 3.1.5 and prior
- SDK versions with nossl tag
- Device firmware that does not use AuthKey for IOTC connection
- Device firmware using the AVAPI module without enabling DTLS mechanism
- Device firmware using P2PTunnel or RDT module
Threats:
Remote attacker could exploit these vulnerabilities by doing the following:
- Sensitive information disclosure
Best practice and Recommendations:
The CERT team encourages users to review ThroughTek security advisory and apply the necessary update: