← Vulnerability feed

Vulnerability record · CVE-2023-6317 · published 9 April 2024

CVE-2023-6317: Lg webos insecure direct object reference vulnerability

Lg · Webos

A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN.  Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA webOS 5.5.0 - 04.50.51 running on OLED55CXPUA webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB   webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA

9.8 CVSS 3.1 Critical EPSS 1.1% · top 36.3% CWE-639 · Insecure direct object reference
9.8CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN.  Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA webOS 5.5.0 - 04.50.51 running on OLED55CXPUA webOS 6.3.3-442 (kisscurl-kinglake) - 03.36.50 running on OLED48C1PUB   webOS 7.3.1-43 (mullet-mebin) - 03.33.85 running on OLED55A23LA

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-6317 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-23730Lg webos improper access control vulnerabilityThe public API error causes for the attacker to be able to bypass API access control.EPSS 1.0%7.8CVE-2022-23731Lg webos permissions and access controls vulnerabilityV8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.EPSS 0.63%7.8CVE-2022-23727Lg webos vulnerabilityThere is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operat…EPSS 0.23%7.8CVE-2020-9759Lg webos download of code without integrity check vulnerabilityA Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is…EPSS 0.48%7.2CVE-2023-6319Lg webos os command injection vulnerabilityA command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 …EPSS 6.4%7.2CVE-2023-6320Lg webos os command injection vulnerabilityA command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A ser…EPSS 3.9%7.2CVE-2023-6318Lg webos os command injection vulnerabilityA command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 throu…EPSS 4.7%8.4CVE-2026-55255Langflow IDOR in responses endpoint allows cross-user flow executionLangflow before 1.9.1 has an insecure direct object reference in the /api/v1/responses endpoint. An authenticated attacker can supply another user's …KEVEPSS 0.89%analysed

Source: NIST National Vulnerability Database (record CVE-2023-6317), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.