CVE-2023-42189
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- tapo/mini smart wi-fi plug firmware · nanoleaf/lightstrip firmware · govee/led strip firmware · switchbot/hub2 firmware · phillips/hue bridge firmware · yeelight/smart lamp firmware · tp-link/smart plug firmware · orein/smart bulb firmware · eve/eve door and window firmware
- Source
- cve@mitre.org
References
- https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdfThird Party Advisory
- https://github.com/project-chip/connectedhomeip/issues/28518Issue Tracking, Third Party Advisory
- https://github.com/project-chip/connectedhomeip/issues/28679Issue Tracking, Third Party Advisory
- https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Remove%20Key%20Set%20Vulnerability%20Report.pdfThird Party Advisory
- https://github.com/project-chip/connectedhomeip/issues/28518Issue Tracking, Third Party Advisory
- https://github.com/project-chip/connectedhomeip/issues/28679Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.