CVE-2023-42189

Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tapo:mini_smart_wi-fi_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tapo:mini_smart_wi-fi_plug:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nanoleaf:lightstrip_firmware:3.5.10:*:*:*:*:*:*:*
cpe:2.3:h:nanoleaf:lightstrip:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:govee:led_strip_firmware:3.00.42:*:*:*:*:*:*:*
cpe:2.3:h:govee:led_strip:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:switchbot:hub2_firmware:1.0-0.8:*:*:*:*:*:*:*
cpe:2.3:h:switchbot:hub2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:phillips:hue_bridge_firmware:1.59.1959097030:*:*:*:*:*:*:*
cpe:2.3:h:phillips:hue_bridge:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:yeelight:smart_lamp_firmware:1.12.69:*:*:*:*:*:*:*
cpe:2.3:h:yeelight:smart_lamp:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:tp-link:smart_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:smart_plug:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:orein:smart_bulb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:orein:smart_bulb:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:eve:eve_door_and_window_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:eve:eve_door_and_window:-:*:*:*:*:*:*:*

History

15 Feb 2024, 19:44

Type Values Removed Values Added
CPE cpe:2.3:h:phillips:hue_hub:-:*:*:*:*:*:*:*
cpe:2.3:o:phillips:hue_hub_firmware:1.59.1959097030:*:*:*:*:*:*:*
cpe:2.3:o:phillips:hue_bridge_firmware:1.59.1959097030:*:*:*:*:*:*:*
cpe:2.3:h:phillips:hue_bridge:-:*:*:*:*:*:*:*
First Time Phillips hue Bridge Firmware
Phillips hue Bridge

16 Oct 2023, 18:36

Type Values Removed Values Added
References (MISC) https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf - (MISC) https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdf - Third Party Advisory
References (MISC) https://github.com/project-chip/connectedhomeip/issues/28518 - (MISC) https://github.com/project-chip/connectedhomeip/issues/28518 - Issue Tracking, Third Party Advisory
References (MISC) https://github.com/project-chip/connectedhomeip/issues/28679 - (MISC) https://github.com/project-chip/connectedhomeip/issues/28679 - Issue Tracking, Third Party Advisory
CPE cpe:2.3:h:nanoleaf:lightstrip:-:*:*:*:*:*:*:*
cpe:2.3:h:yeelight:smart_lamp:-:*:*:*:*:*:*:*
cpe:2.3:o:switchbot:hub2_firmware:1.0-0.8:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:smart_plug:-:*:*:*:*:*:*:*
cpe:2.3:h:orein:smart_bulb:-:*:*:*:*:*:*:*
cpe:2.3:h:switchbot:hub2:-:*:*:*:*:*:*:*
cpe:2.3:o:govee:led_strip_firmware:3.00.42:*:*:*:*:*:*:*
cpe:2.3:o:eve:eve_door_and_window_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:nanoleaf:lightstrip_firmware:3.5.10:*:*:*:*:*:*:*
cpe:2.3:o:phillips:hue_hub_firmware:1.59.1959097030:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:smart_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:orein:smart_bulb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:yeelight:smart_lamp_firmware:1.12.69:*:*:*:*:*:*:*
cpe:2.3:h:phillips:hue_hub:-:*:*:*:*:*:*:*
cpe:2.3:h:eve:eve_door_and_window:-:*:*:*:*:*:*:*
cpe:2.3:h:tapo:mini_smart_wi-fi_plug:-:*:*:*:*:*:*:*
cpe:2.3:o:tapo:mini_smart_wi-fi_plug_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:govee:led_strip:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Phillips hue Hub
Tp-link smart Plug
Yeelight smart Lamp
Tapo mini Smart Wi-fi Plug Firmware
Phillips
Phillips hue Hub Firmware
Yeelight
Govee led Strip
Govee led Strip Firmware
Tp-link smart Plug Firmware
Tp-link
Orein smart Bulb
Switchbot hub2
Eve eve Door And Window
Tapo mini Smart Wi-fi Plug
Yeelight smart Lamp Firmware
Switchbot
Nanoleaf lightstrip Firmware
Switchbot hub2 Firmware
Eve eve Door And Window Firmware
Orein
Orein smart Bulb Firmware
Nanoleaf
Nanoleaf lightstrip
Govee
Tapo
Eve
CWE CWE-732

10 Oct 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-10 03:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-42189

Mitre link : CVE-2023-42189

CVE.ORG link : CVE-2023-42189


JSON object : View

Products Affected

tp-link

  • smart_plug
  • smart_plug_firmware

switchbot

  • hub2
  • hub2_firmware

eve

  • eve_door_and_window
  • eve_door_and_window_firmware

nanoleaf

  • lightstrip
  • lightstrip_firmware

tapo

  • mini_smart_wi-fi_plug
  • mini_smart_wi-fi_plug_firmware

govee

  • led_strip
  • led_strip_firmware

phillips

  • hue_bridge_firmware
  • hue_bridge

orein

  • smart_bulb
  • smart_bulb_firmware

yeelight

  • smart_lamp
  • smart_lamp_firmware
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource