First published: Tue Oct 10 2023(Updated: )
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tapo Mini Smart Wi-Fi Plug Firmware | ||
Tapo Mini Smart Wi-Fi Plug Firmware | ||
Nanoleaf Lightstrip Firmware | =3.5.10 | |
Nanoleaf Lightstrip Firmware | ||
Govee LED Strip Firmware | =3.00.42 | |
Govee LED Strip Firmware | ||
switchBot Hub2 | =1.0-0.8 | |
switchBot Hub2 | ||
Philips Hue Hub Firmware | =1.59.1959097030 | |
Philips Hue Bridge | ||
Yeelight Smart Lamp Firmware | =1.12.69 | |
Yeelight Smart Lamp Firmware | ||
TP-Link Smart Plug | ||
TP-Link Smart Plug Firmware | ||
orein smart bulb | ||
orein smart bulb firmware | ||
Eve Eve Door and Window | ||
Eve Door and Window Firmware | ||
All of | ||
Tapo Mini Smart Wi-Fi Plug Firmware | ||
Tapo Mini Smart Wi-Fi Plug Firmware | ||
All of | ||
Nanoleaf Lightstrip Firmware | =3.5.10 | |
Nanoleaf Lightstrip Firmware | ||
All of | ||
Govee LED Strip Firmware | =3.00.42 | |
Govee LED Strip Firmware | ||
All of | ||
switchBot Hub2 | =1.0-0.8 | |
switchBot Hub2 | ||
All of | ||
Philips Hue Bridge | =1.59.1959097030 | |
Philips Hue Bridge | ||
All of | ||
Yeelight Smart Lamp Firmware | =1.12.69 | |
Yeelight Smart Lamp Firmware | ||
All of | ||
TP-Link Smart Plug | ||
TP-Link Smart Plug Firmware | ||
All of | ||
orein smart bulb | ||
orein smart bulb firmware | ||
All of | ||
Eve Eve Door and Window | ||
Eve Door and Window Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-42189 is high with a severity value of 7.5.
Connectivity Standards Alliance Matter Official SDK v.1.1.0.0, Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 are affected by CVE-2023-42189.
A remote attacker can exploit CVE-2023-42189 to cause a denial of service.
Tapo Mini Smart Wi-fi Plugs are not vulnerable to CVE-2023-42189.
The fix for CVE-2023-42189 is not mentioned in the provided references, please refer to the official vendor's website or contact the vendor for a fix.