HIGH · 7.5

CVE-2023-42189

Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue h...

Vulnerability Description

Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
TapoMini Smart Wi-Fi Plug Firmware-
TapoMini Smart Wi-Fi Plug-
NanoleafLightstrip Firmware3.5.10
NanoleafLightstrip-
GoveeLed Strip Firmware3.00.42
GoveeLed Strip-
SwitchbotHub2 Firmware1.0-0.8
SwitchbotHub2-
PhillipsHue Bridge Firmware1.59.1959097030
PhillipsHue Bridge-
YeelightSmart Lamp Firmware1.12.69
YeelightSmart Lamp-
Tp-LinkSmart Plug Firmware-
Tp-LinkSmart Plug-
OreinSmart Bulb Firmware-
OreinSmart Bulb-
EveEve Door And Window Firmware-
EveEve Door And Window-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-42189?

CVE-2023-42189 is a vulnerability with a CVSS score of 7.5 (HIGH). Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue h...

How severe is CVE-2023-42189?

CVE-2023-42189 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-42189?

Check the references section above for vendor advisories and patch information. Affected products include: Tapo Mini Smart Wi-Fi Plug Firmware, Tapo Mini Smart Wi-Fi Plug, Nanoleaf Lightstrip Firmware, Nanoleaf Lightstrip, Govee Led Strip Firmware.