Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
References
Link | Resource |
---|---|
https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf | Third Party Advisory |
https://github.com/project-chip/connectedhomeip/issues/28518 | Issue Tracking Third Party Advisory |
https://github.com/project-chip/connectedhomeip/issues/28679 | Issue Tracking Third Party Advisory |
https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf | Third Party Advisory |
https://github.com/project-chip/connectedhomeip/issues/28518 | Issue Tracking Third Party Advisory |
https://github.com/project-chip/connectedhomeip/issues/28679 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
History
21 Nov 2024, 08:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf - Third Party Advisory | |
References | () https://github.com/project-chip/connectedhomeip/issues/28518 - Issue Tracking, Third Party Advisory | |
References | () https://github.com/project-chip/connectedhomeip/issues/28679 - Issue Tracking, Third Party Advisory |
15 Feb 2024, 19:44
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-10 03:15
Updated : 2024-11-21 08:22
NVD link : CVE-2023-42189
Mitre link : CVE-2023-42189
CVE.ORG link : CVE-2023-42189
JSON object : View
Products Affected
govee
- led_strip_firmware
- led_strip
phillips
- hue_bridge
- hue_bridge_firmware
switchbot
- hub2
- hub2_firmware
yeelight
- smart_lamp_firmware
- smart_lamp
eve
- eve_door_and_window
- eve_door_and_window_firmware
orein
- smart_bulb_firmware
- smart_bulb
tp-link
- smart_plug_firmware
- smart_plug
nanoleaf
- lightstrip_firmware
- lightstrip
tapo
- mini_smart_wi-fi_plug_firmware
- mini_smart_wi-fi_plug
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource