Description
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
Published: 2023-10-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Eve Eve Door And Window Eve Door And Window Firmware
Govee Led Strip Led Strip Firmware
Nanoleaf Lightstrip Lightstrip Firmware
Orein Smart Bulb Smart Bulb Firmware
Phillips Hue Bridge Hue Bridge Firmware
Switchbot Hub2 Hub2 Firmware
Tapo Mini Smart Wi-fi Plug Mini Smart Wi-fi Plug Firmware
Tp-link Smart Plug Smart Plug Firmware
Yeelight Smart Lamp Smart Lamp Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-26T21:34:19.757Z

Reserved: 2023-09-08T00:00:00.000Z

Link: CVE-2023-42189

cve-icon Vulnrichment

Updated: 2024-08-02T19:16:51.051Z

cve-icon NVD

Status : Modified

Published: 2023-10-10T03:15:09.530

Modified: 2024-11-21T08:22:22.537

Link: CVE-2023-42189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses