CVE-2023-42189

Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tapo:mini_smart_wi-fi_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tapo:mini_smart_wi-fi_plug:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nanoleaf:lightstrip_firmware:3.5.10:*:*:*:*:*:*:*
cpe:2.3:h:nanoleaf:lightstrip:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:govee:led_strip_firmware:3.00.42:*:*:*:*:*:*:*
cpe:2.3:h:govee:led_strip:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:switchbot:hub2_firmware:1.0-0.8:*:*:*:*:*:*:*
cpe:2.3:h:switchbot:hub2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:phillips:hue_bridge_firmware:1.59.1959097030:*:*:*:*:*:*:*
cpe:2.3:h:phillips:hue_bridge:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:yeelight:smart_lamp_firmware:1.12.69:*:*:*:*:*:*:*
cpe:2.3:h:yeelight:smart_lamp:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:tp-link:smart_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:smart_plug:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:orein:smart_bulb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:orein:smart_bulb:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:eve:eve_door_and_window_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:eve:eve_door_and_window:-:*:*:*:*:*:*:*

History

15 Feb 2024, 19:44

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-10 03:15

Updated : 2024-02-15 19:44


NVD link : CVE-2023-42189

Mitre link : CVE-2023-42189

CVE.ORG link : CVE-2023-42189


JSON object : View

Products Affected

orein

  • smart_bulb
  • smart_bulb_firmware

yeelight

  • smart_lamp
  • smart_lamp_firmware

eve

  • eve_door_and_window_firmware
  • eve_door_and_window

tp-link

  • smart_plug_firmware
  • smart_plug

nanoleaf

  • lightstrip
  • lightstrip_firmware

phillips

  • hue_bridge_firmware
  • hue_bridge

tapo

  • mini_smart_wi-fi_plug
  • mini_smart_wi-fi_plug_firmware

switchbot

  • hub2_firmware
  • hub2

govee

  • led_strip
  • led_strip_firmware
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource