CVE-2023-42189

Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tapo:mini_smart_wi-fi_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tapo:mini_smart_wi-fi_plug:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nanoleaf:lightstrip_firmware:3.5.10:*:*:*:*:*:*:*
cpe:2.3:h:nanoleaf:lightstrip:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:govee:led_strip_firmware:3.00.42:*:*:*:*:*:*:*
cpe:2.3:h:govee:led_strip:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:switchbot:hub2_firmware:1.0-0.8:*:*:*:*:*:*:*
cpe:2.3:h:switchbot:hub2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:phillips:hue_bridge_firmware:1.59.1959097030:*:*:*:*:*:*:*
cpe:2.3:h:phillips:hue_bridge:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:yeelight:smart_lamp_firmware:1.12.69:*:*:*:*:*:*:*
cpe:2.3:h:yeelight:smart_lamp:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:tp-link:smart_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:smart_plug:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:orein:smart_bulb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:orein:smart_bulb:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:eve:eve_door_and_window_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:eve:eve_door_and_window:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:22

Type Values Removed Values Added
References () https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf - Third Party Advisory () https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf - Third Party Advisory
References () https://github.com/project-chip/connectedhomeip/issues/28518 - Issue Tracking, Third Party Advisory () https://github.com/project-chip/connectedhomeip/issues/28518 - Issue Tracking, Third Party Advisory
References () https://github.com/project-chip/connectedhomeip/issues/28679 - Issue Tracking, Third Party Advisory () https://github.com/project-chip/connectedhomeip/issues/28679 - Issue Tracking, Third Party Advisory

15 Feb 2024, 19:44

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-10 03:15

Updated : 2024-11-21 08:22


NVD link : CVE-2023-42189

Mitre link : CVE-2023-42189

CVE.ORG link : CVE-2023-42189


JSON object : View

Products Affected

govee

  • led_strip_firmware
  • led_strip

phillips

  • hue_bridge
  • hue_bridge_firmware

switchbot

  • hub2
  • hub2_firmware

yeelight

  • smart_lamp_firmware
  • smart_lamp

eve

  • eve_door_and_window
  • eve_door_and_window_firmware

orein

  • smart_bulb_firmware
  • smart_bulb

tp-link

  • smart_plug_firmware
  • smart_plug

nanoleaf

  • lightstrip_firmware
  • lightstrip

tapo

  • mini_smart_wi-fi_plug_firmware
  • mini_smart_wi-fi_plug
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource