CVE-2023-42189
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
Published:Oct 10, 2023
Last Modified:Nov 26, 2024
EPS:Oct 10, 2023
EPSS Score:0.00523
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Eve
Product
Eve Door And Window
Eve
Eve Door And Window
Vendor
Eve
Product
Eve Door And Window Firmware
Eve
Eve Door And Window Firmware
Vendor
Govee
Product
Led Strip
Govee
Led Strip
Vendor
Govee
Product
Led Strip Firmware
Govee
Led Strip Firmware
Vendor
Nanoleaf
Product
Lightstrip
Nanoleaf
Lightstrip
Vendor
Nanoleaf
Product
Lightstrip Firmware
Nanoleaf
Lightstrip Firmware
Vendor
Orein
Product
Smart Bulb
Orein
Smart Bulb
Vendor
Orein
Product
Smart Bulb Firmware
Orein
Smart Bulb Firmware
Vendor
Phillips
Product
Hue Bridge
Phillips
Hue Bridge
Vendor
Phillips
Product
Hue Bridge Firmware
Phillips
Hue Bridge Firmware
Vendor
Switchbot
Product
Hub2
Switchbot
Hub2
Vendor
Switchbot
Product
Hub2 Firmware
Switchbot
Hub2 Firmware
Vendor
Tapo
Product
Mini Smart Wi-fi Plug
Tapo
Mini Smart Wi-fi Plug
Vendor
Tapo
Product
Mini Smart Wi-fi Plug Firmware
Tapo
Mini Smart Wi-fi Plug Firmware
Vendor
Tp-link
Product
Smart Plug
Tp-link
Smart Plug
Vendor
Tp-link
Product
Smart Plug Firmware
Tp-link
Smart Plug Firmware
Vendor
Yeelight
Product
Smart Lamp
Yeelight
Smart Lamp
Vendor
Yeelight
Product
Smart Lamp Firmware
Yeelight
Smart Lamp Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
