CVE-2023-45956: High severity govee led strip firmware vulnerability
Published Oct 30, 2023
·Updated
An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.
Affected Software
2 affected components
All of the following
Govee Led Strip Firmware=3.00.42
Govee LED Strip
Event History
Oct 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-45956?
The severity of CVE-2023-45956 is high with a CVSS score of 7.5.
2
What software versions are affected by CVE-2023-45956?
Govee LED Strip firmware version 3.00.42 is affected by CVE-2023-45956.
3
How can attackers exploit CVE-2023-45956?
Attackers can cause a denial of service by sending crafted Move and MoveWithOnoff commands to Govee LED Strip firmware version 3.00.42.
4
Is Govee LED Strip version 3.00.42 vulnerable to CVE-2023-45956?
Yes, Govee LED Strip firmware version 3.00.42 is vulnerable to CVE-2023-45956.
5
Where can I find more information about CVE-2023-45956?
You can find more information about CVE-2023-45956 in the [GitHub vulnerability report](https://github.com/IoT-Fuzz/IoT-Fuzz/blob/main/Govee%20LED%20Strip%20Vulnerability%20Report.pdf).