Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.
History

Fri, 20 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Dec 2024 09:45:00 +0000

Type Values Removed Values Added
Description Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions before 5.9.
Title Gaining remote control over Govee devices
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2024-12-19T09:39:31.393Z

Updated: 2024-12-20T17:56:46.028Z

Reserved: 2023-08-30T08:30:57.983Z

Link: CVE-2023-4617

cve-icon Vulnrichment

Updated: 2024-12-20T17:56:39.389Z

cve-icon NVD

Status : Received

Published: 2024-12-19T10:15:13.147

Modified: 2024-12-19T10:15:13.147

Link: CVE-2023-4617

cve-icon Redhat

No data.