Your review has been sent successfully

ThroughTek Update

2435
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

18 August, 2021

● Critical

2021-3382

All

Description:

ThroughTek has released a security update to address a vulnerability in the following versions of :

  • Kalay P2P Software Development Kit (SDK) :
    • Versions 3.1.5 and prior
    • SDK versions with the nossl tag
    • Device firmware that does not use AuthKey for IOTC connection
    • Device firmware using the AVAPI module without enabling DTLS mechanism
    • Device firmware using P2PTunnel or RDT module

Threats:

Remote attacker could exploit this vulnerability by doing the following:

  • Sensitive information disclosure
  • Execute arbitrary code

Best practice and Recommendations:

The CERT team encourages users to review ThroughTek security advisory and apply the necessary update:

Last updated at 18 August, 2021

Rate the content

rate-icon
up icon