Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-42189


Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.


Published

2023-10-10T03:15:09.530

Last Modified

2024-11-21T08:22:22.537

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-732

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tapo mini_smart_wi-fi_plug_firmware - Yes
Hardware tapo mini_smart_wi-fi_plug - No
Operating System nanoleaf lightstrip_firmware 3.5.10 Yes
Hardware nanoleaf lightstrip - No
Operating System govee led_strip_firmware 3.00.42 Yes
Hardware govee led_strip - No
Operating System switchbot hub2_firmware 1.0-0.8 Yes
Hardware switchbot hub2 - No
Operating System phillips hue_bridge_firmware 1.59.1959097030 Yes
Hardware phillips hue_bridge - No
Operating System yeelight smart_lamp_firmware 1.12.69 Yes
Hardware yeelight smart_lamp - No
Operating System tp-link smart_plug_firmware - Yes
Hardware tp-link smart_plug - No
Operating System orein smart_bulb_firmware - Yes
Hardware orein smart_bulb - No
Operating System eve eve_door_and_window_firmware - Yes
Hardware eve eve_door_and_window - No

References