CVE-2023-42189

Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tapo:mini_smart_wi-fi_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tapo:mini_smart_wi-fi_plug:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nanoleaf:lightstrip_firmware:3.5.10:*:*:*:*:*:*:*
cpe:2.3:h:nanoleaf:lightstrip:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:govee:led_strip_firmware:3.00.42:*:*:*:*:*:*:*
cpe:2.3:h:govee:led_strip:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:switchbot:hub2_firmware:1.0-0.8:*:*:*:*:*:*:*
cpe:2.3:h:switchbot:hub2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:phillips:hue_bridge_firmware:1.59.1959097030:*:*:*:*:*:*:*
cpe:2.3:h:phillips:hue_bridge:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:yeelight:smart_lamp_firmware:1.12.69:*:*:*:*:*:*:*
cpe:2.3:h:yeelight:smart_lamp:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:tp-link:smart_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:smart_plug:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:orein:smart_bulb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:orein:smart_bulb:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:eve:eve_door_and_window_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:eve:eve_door_and_window:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:22

Type Values Removed Values Added
References () https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf - Third Party Advisory () https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf - Third Party Advisory
References () https://github.com/project-chip/connectedhomeip/issues/28518 - Issue Tracking, Third Party Advisory () https://github.com/project-chip/connectedhomeip/issues/28518 - Issue Tracking, Third Party Advisory
References () https://github.com/project-chip/connectedhomeip/issues/28679 - Issue Tracking, Third Party Advisory () https://github.com/project-chip/connectedhomeip/issues/28679 - Issue Tracking, Third Party Advisory

15 Feb 2024, 19:44

Type Values Removed Values Added
CPE cpe:2.3:h:phillips:hue_hub:-:*:*:*:*:*:*:*
cpe:2.3:o:phillips:hue_hub_firmware:1.59.1959097030:*:*:*:*:*:*:*
cpe:2.3:o:phillips:hue_bridge_firmware:1.59.1959097030:*:*:*:*:*:*:*
cpe:2.3:h:phillips:hue_bridge:-:*:*:*:*:*:*:*
First Time Phillips hue Bridge Firmware
Phillips hue Bridge

16 Oct 2023, 18:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Phillips hue Hub
Tp-link smart Plug
Yeelight smart Lamp
Tapo mini Smart Wi-fi Plug Firmware
Phillips
Phillips hue Hub Firmware
Yeelight
Govee led Strip
Govee led Strip Firmware
Tp-link smart Plug Firmware
Tp-link
Orein smart Bulb
Switchbot hub2
Eve eve Door And Window
Tapo mini Smart Wi-fi Plug
Yeelight smart Lamp Firmware
Switchbot
Nanoleaf lightstrip Firmware
Switchbot hub2 Firmware
Eve eve Door And Window Firmware
Orein
Orein smart Bulb Firmware
Nanoleaf
Nanoleaf lightstrip
Govee
Tapo
Eve
CPE cpe:2.3:h:nanoleaf:lightstrip:-:*:*:*:*:*:*:*
cpe:2.3:h:yeelight:smart_lamp:-:*:*:*:*:*:*:*
cpe:2.3:o:switchbot:hub2_firmware:1.0-0.8:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:smart_plug:-:*:*:*:*:*:*:*
cpe:2.3:h:orein:smart_bulb:-:*:*:*:*:*:*:*
cpe:2.3:h:switchbot:hub2:-:*:*:*:*:*:*:*
cpe:2.3:o:govee:led_strip_firmware:3.00.42:*:*:*:*:*:*:*
cpe:2.3:o:eve:eve_door_and_window_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:nanoleaf:lightstrip_firmware:3.5.10:*:*:*:*:*:*:*
cpe:2.3:o:phillips:hue_hub_firmware:1.59.1959097030:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:smart_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:orein:smart_bulb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:yeelight:smart_lamp_firmware:1.12.69:*:*:*:*:*:*:*
cpe:2.3:h:phillips:hue_hub:-:*:*:*:*:*:*:*
cpe:2.3:h:eve:eve_door_and_window:-:*:*:*:*:*:*:*
cpe:2.3:h:tapo:mini_smart_wi-fi_plug:-:*:*:*:*:*:*:*
cpe:2.3:o:tapo:mini_smart_wi-fi_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:govee:led_strip:-:*:*:*:*:*:*:*
CWE CWE-732
References (MISC) https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf - (MISC) https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf - Third Party Advisory
References (MISC) https://github.com/project-chip/connectedhomeip/issues/28518 - (MISC) https://github.com/project-chip/connectedhomeip/issues/28518 - Issue Tracking, Third Party Advisory
References (MISC) https://github.com/project-chip/connectedhomeip/issues/28679 - (MISC) https://github.com/project-chip/connectedhomeip/issues/28679 - Issue Tracking, Third Party Advisory

10 Oct 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-10 03:15

Updated : 2024-11-21 08:22


NVD link : CVE-2023-42189

Mitre link : CVE-2023-42189

CVE.ORG link : CVE-2023-42189


JSON object : View

Products Affected

nanoleaf

  • lightstrip_firmware
  • lightstrip

tp-link

  • smart_plug_firmware
  • smart_plug

govee

  • led_strip_firmware
  • led_strip

switchbot

  • hub2_firmware
  • hub2

phillips

  • hue_bridge_firmware
  • hue_bridge

orein

  • smart_bulb_firmware
  • smart_bulb

eve

  • eve_door_and_window_firmware
  • eve_door_and_window

tapo

  • mini_smart_wi-fi_plug_firmware
  • mini_smart_wi-fi_plug

yeelight

  • smart_lamp_firmware
  • smart_lamp
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource