CVE-2023-42189
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
Vulnerabilidad de permisos inseguros en Connectivity Standards Alliance Matter Official SDK v.1.1.0.0, Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030 y yeelight smart lamp v.1.12.69 permite que un atacante remoto provoque una denegaciĆ³n de servicio mediante un script manipulado para la funciĆ³n KeySetRemove.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-09-08 CVE Reserved
- 2023-10-10 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf | Third Party Advisory | |
https://github.com/project-chip/connectedhomeip/issues/28518 | Issue Tracking | |
https://github.com/project-chip/connectedhomeip/issues/28679 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tapo Search vendor "Tapo" | Mini Smart Wi-fi Plug Firmware Search vendor "Tapo" for product "Mini Smart Wi-fi Plug Firmware" | - | - |
Affected
| in | Tapo Search vendor "Tapo" | Mini Smart Wi-fi Plug Search vendor "Tapo" for product "Mini Smart Wi-fi Plug" | - | - |
Safe
|
Nanoleaf Search vendor "Nanoleaf" | Lightstrip Firmware Search vendor "Nanoleaf" for product "Lightstrip Firmware" | 3.5.10 Search vendor "Nanoleaf" for product "Lightstrip Firmware" and version "3.5.10" | - |
Affected
| in | Nanoleaf Search vendor "Nanoleaf" | Lightstrip Search vendor "Nanoleaf" for product "Lightstrip" | - | - |
Safe
|
Govee Search vendor "Govee" | Led Strip Firmware Search vendor "Govee" for product "Led Strip Firmware" | 3.00.42 Search vendor "Govee" for product "Led Strip Firmware" and version "3.00.42" | - |
Affected
| in | Govee Search vendor "Govee" | Led Strip Search vendor "Govee" for product "Led Strip" | - | - |
Safe
|
Switchbot Search vendor "Switchbot" | Hub2 Firmware Search vendor "Switchbot" for product "Hub2 Firmware" | 1.0-0.8 Search vendor "Switchbot" for product "Hub2 Firmware" and version "1.0-0.8" | - |
Affected
| in | Switchbot Search vendor "Switchbot" | Hub2 Search vendor "Switchbot" for product "Hub2" | - | - |
Safe
|
Phillips Search vendor "Phillips" | Hue Bridge Firmware Search vendor "Phillips" for product "Hue Bridge Firmware" | 1.59.1959097030 Search vendor "Phillips" for product "Hue Bridge Firmware" and version "1.59.1959097030" | - |
Affected
| in | Phillips Search vendor "Phillips" | Hue Bridge Search vendor "Phillips" for product "Hue Bridge" | - | - |
Safe
|
Yeelight Search vendor "Yeelight" | Smart Lamp Firmware Search vendor "Yeelight" for product "Smart Lamp Firmware" | 1.12.69 Search vendor "Yeelight" for product "Smart Lamp Firmware" and version "1.12.69" | - |
Affected
| in | Yeelight Search vendor "Yeelight" | Smart Lamp Search vendor "Yeelight" for product "Smart Lamp" | - | - |
Safe
|
Tp-link Search vendor "Tp-link" | Smart Plug Firmware Search vendor "Tp-link" for product "Smart Plug Firmware" | - | - |
Affected
| in | Tp-link Search vendor "Tp-link" | Smart Plug Search vendor "Tp-link" for product "Smart Plug" | - | - |
Safe
|
Orein Search vendor "Orein" | Smart Bulb Firmware Search vendor "Orein" for product "Smart Bulb Firmware" | - | - |
Affected
| in | Orein Search vendor "Orein" | Smart Bulb Search vendor "Orein" for product "Smart Bulb" | - | - |
Safe
|
Eve Search vendor "Eve" | Eve Door And Window Firmware Search vendor "Eve" for product "Eve Door And Window Firmware" | - | - |
Affected
| in | Eve Search vendor "Eve" | Eve Door And Window Search vendor "Eve" for product "Eve Door And Window" | - | - |
Safe
|