ThroughTek Update
2682Warning Date
Severity Level
Warning Number
Target Sector
18 August, 2021
● Critical
2021-3382
All
Description:
ThroughTek has released a security update to address a vulnerability in the following versions of :
- Kalay P2P Software Development Kit (SDK) :
- Versions 3.1.5 and prior
- SDK versions with the nossl tag
- Device firmware that does not use AuthKey for IOTC connection
- Device firmware using the AVAPI module without enabling DTLS mechanism
- Device firmware using P2PTunnel or RDT module
Threats:
Remote attacker could exploit this vulnerability by doing the following:
- Sensitive information disclosure
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review ThroughTek security advisory and apply the necessary update: